cleantalk
Vulnerabilities and Security Researches

Pricing Table by Supsystic, 8ecbeaaa-7986-4109-a56a-3d67496330f2

Published on
-
Research Description
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.9 Pricing Table by Supsystic &lt; 1.8.9 - Authenticated SQL Injections The GET parameter sidx and sord are used in a SQL statement without being sanitised when searching for pricing tables in the dashboard, leading to an authenticated SQL Injection issues.
Affected versions
max 1.8.9.
Status
vulnerable