CVE-2021-24345
14.06.2021, 14:15
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.
Vendor | Product | Version |
---|---|---|
sendit_project | sendit | 𝑥 ≤ 2.5.1 |
𝑥
= Vulnerable software versions