In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2021-06-21T19:18:14

Updated: 2021-06-21T19:18:14

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-24361

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-21T20:15:08.347

Modified: 2021-06-24T19:44:22.053


Link: CVE-2021-24361

JSON object: View

cve-icon Redhat Information

No data.

CWE