CVE-2021-24285
14.05.2021, 12:15
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.
Vendor | Product | Version |
---|---|---|
cars-seller-auto-classifieds-script_project | cars-seller-auto-classifieds-script | 𝑥 ≤ 2.1.0 |
𝑥
= Vulnerable software versions
References