WordPress Plugin Vulnerabilities

FV Flowplayer Video Player < 7.3.19.727 - SQL Injection

Description

Lack of sanitisation in the order and order_by variable in the getListPageData() function could allow SQL Injection attacks

Affects Plugins

Fixed in 7.3.19.727

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Tin Duong
Verified
No

Timeline

Publicly Published
2019-07-11 (about 6 years ago)
Added
2019-07-12 (about 6 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other