CVE-2021-24786
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
- Affected products
- Download Monitor
- Wpchill Download Monitor
- < 4.4.5
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 17.3% (97th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2022-01-03
CVE-2021-24786 at NVD
5 known exploits for CVE-2021-24786
Proof-of-concept code and exploit modules indexed by Sploitus