Описание
SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.
EPSS
Процентиль: 7%
0.00028
Низкий
7.1 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 7.1
github
17 дней назад
SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.
EPSS
Процентиль: 7%
0.00028
Низкий
7.1 High
CVSS3
Дефекты
CWE-89