Логотип exploitDog
bind:CVE-2021-24946
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24946

Количество 2

Количество 2

nvd логотип

CVE-2021-24946

около 4 лет назад

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-8cmg-w5hw-x6p6

около 4 лет назад

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24946

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

CVSS3: 9.8
60%
Средний
около 4 лет назад
github логотип
GHSA-8cmg-w5hw-x6p6

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

60%
Средний
около 4 лет назад

Уязвимостей на страницу