Description


The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.

Weaknesses



CWE-89


CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

8.2 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-09-09T17:15:14.053Z

4 years ago

Last modified

2024-11-21T05:16:48.457Z

1 year ago