mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 14:19:30 +02:00
905 B
905 B
CVE-2021-25023
Description
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection
POC
Reference
- https://wpscan.com/vulnerability/4a27d374-f690-4a8a-987a-9e0f56bbe143
- https://wpscan.com/vulnerability/4a27d374-f690-4a8a-987a-9e0f56bbe143
Github
No PoCs found on GitHub currently.