CVE-2021-24138

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:ajdg:adrotate:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-03-18 08:15

Updated : 2021-03-24 05:27


NVD link : CVE-2021-24138

Mitre link : CVE-2021-24138


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

ajdg

  • adrotate