Lack of sanitisation in the order and order_by variable in the getListPageData() function could allow SQL Injection attacks
SQLI
Tin Duong
No
2019-07-11 (about 2 years ago)
2019-07-12 (about 2 years ago)
2020-09-22 (about 1 years ago)