mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-02 07:51:39 +02:00
18 lines
751 B
Markdown
18 lines
751 B
Markdown
### [CVE-2021-24456](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24456)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/929ad37d-9cdb-4117-8cd3-cf7130a7c9d4
|
|
|
|
#### Github
|
|
- https://github.com/20142995/nuclei-templates
|
|
|