Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24456
HistoryAug 02, 2021 - 10:32 a.m.

CVE-2021-24456 Quiz Maker < 6.2.0.9 - Multiple Authenticated Blind SQL Injections

2021-08-0210:32:02
CWE-89
WPScan
www.cve.org
1
cve-2021-24456
quiz maker
wordpress plugin
sql injection
admin dashboard

EPSS

0.001

Percentile

37.0%

The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard

CNA Affected

[
  {
    "product": "Quiz Maker",
    "vendor": "Ays Pro",
    "versions": [
      {
        "lessThan": "6.2.0.9",
        "status": "affected",
        "version": "6.2.0.9",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

37.0%

Related for CVELIST:CVE-2021-24456