{"containers":{"cna":{"affected":[{"product":"Quiz Maker","vendor":"Ays Pro","versions":[{"lessThan":"6.2.0.9","status":"affected","version":"6.2.0.9","versionType":"custom"}]}],"credits":[{"lang":"en","value":"To Quang Duong"}],"descriptions":[{"lang":"en","value":"The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 SQL Injection","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2021-08-02T10:32:02.000Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["x_refsource_MISC"],"url":"https://wpscan.com/vulnerability/929ad37d-9cdb-4117-8cd3-cf7130a7c9d4"}],"source":{"discovery":"UNKNOWN"},"title":"Quiz Maker < 6.2.0.9 - Multiple Authenticated Blind SQL Injections","x_generator":"WPScan CVE Generator","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"contact@wpscan.com","ID":"CVE-2021-24456","STATE":"PUBLIC","TITLE":"Quiz Maker < 6.2.0.9 - Multiple Authenticated Blind SQL Injections"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Quiz Maker","version":{"version_data":[{"version_affected":"<","version_name":"6.2.0.9","version_value":"6.2.0.9"}]}}]},"vendor_name":"Ays Pro"}]}},"credit":[{"lang":"eng","value":"To Quang Duong"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard"}]},"generator":"WPScan CVE Generator","problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-89 SQL Injection"}]}]},"references":{"reference_data":[{"name":"https://wpscan.com/vulnerability/929ad37d-9cdb-4117-8cd3-cf7130a7c9d4","refsource":"MISC","url":"https://wpscan.com/vulnerability/929ad37d-9cdb-4117-8cd3-cf7130a7c9d4"}]},"source":{"discovery":"UNKNOWN"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T19:35:19.195Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://wpscan.com/vulnerability/929ad37d-9cdb-4117-8cd3-cf7130a7c9d4"}]}]},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2021-24456","datePublished":"2021-08-02T10:32:02.000Z","dateReserved":"2021-01-14T00:00:00.000Z","dateUpdated":"2024-08-03T19:35:19.195Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}