cleantalk
Vulnerabilities and Security Researches

Email Log, CVE-2021-24758

CVE, Research URL

CVE-2021-24758

Application

Email Log

Published on
Nov 17, 2021
Research Description
The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections
Affected versions
Min -, max 2.2.3.
Status
vulnerable