CVE-2021-24390

CVE-2021-24390: Alipay <= 3.7.2 - Authenticated SQL Injection

Vendor Unknown
Product WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件
Weakness CWE-89 · SQLi
Published September 6, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.

Key dates

02Disclosure timeline

September 6, 2021 CVE published
August 3, 2024 Record updated