cleantalk
Vulnerabilities and Security Researches

BSK PDF Manager, CVE-2021-24860

CVE, Research URL

CVE-2021-24860

Application

BSK PDF Manager

Published on
Nov 29, 2021
Research Description
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue
Affected versions
Min -, max 3.1.2.
Status
vulnerable