CVE-2021-24951

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
13/12/2021
Last modified:
16/12/2021

Description

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:* 4.1.4 (excluding)