CVE-2021-24860
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue
- Affected products
- Bsk Pdf Manager
- Bannersky Bsk Pdf Manager
- < 3.1.2
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.3% (67th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2021-11-29
CVE-2021-24860 at NVD
1 known exploit for CVE-2021-24860
Proof-of-concept code and exploit modules indexed by Sploitus