Vulnerabilities > CVE-2021-24390 - Unspecified vulnerability in Alipay Project Alipay
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A proid GET parameter of the WordPress???Alipay|???Tenpay|??PayPal???? WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |