Back to search
CVE-2021-24557
Published: Aug 23, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.
| Vendor | Product | Versions |
|---|---|---|
Unknown | M-vSlider | affected 2.1.3 - <= 2.1.3 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now