Security Advisory

CVE-2021-24625

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-11-08 17:34:48
Last updated 2024-08-03 19:35:20
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before using them in a SQL statement, leading to a SQL injection when adding a category