mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-30 17:29:30 +02:00
874 B
874 B
CVE-2021-25064
Description
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.
POC
Reference
- https://wpscan.com/vulnerability/30c70315-3c17-41f0-a12f-7e3f793e259c
- https://wpscan.com/vulnerability/30c70315-3c17-41f0-a12f-7e3f793e259c
Github
No PoCs found on GitHub currently.