cleantalk
Vulnerabilities and Security Researches

Download Monitor, CVE-2021-24786

CVE, Research URL

CVE-2021-24786

Application

Download Monitor

Published on
Jan 03, 2022
Research Description
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Affected versions
max 4.4.5.
Status
vulnerable