mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-26 17:47:58 +02:00
977 B
977 B
CVE-2021-24952
Description
The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.
POC
Reference
- https://wpscan.com/vulnerability/cbb8fa9f-1c84-4410-ae86-64cb1771ce78
- https://wpscan.com/vulnerability/cbb8fa9f-1c84-4410-ae86-64cb1771ce78
Github
No PoCs found on GitHub currently.