← voltar
CVE-2021-24149

Modern Events Calendar Lite < 5.16.6 - Authenticated SQL Injection

EPSS 1.5%CWE-89
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →