CVE-2021-26609
Description
A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information.
CWE
- CWE-89 — CWE-89 SQL Injection
Affected
- Mangboard / WordPress Mangboard — v=1.9.9 ≤1.9.9 [affected]
CVSS
- 3.1 score=7.5 severity=HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References
Source
cvelistV5-main/cves/2021/26xxx/CVE-2021-26609.json