CVE-2021-24848
13.12.2021, 11:15
The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection
Vendor | Product | Version |
---|---|---|
frenify | mediamatic | 𝑥 < 2.8.1 |
𝑥
= Vulnerable software versions