CVE-2021-47872
HIGHSEO Panel < 4.9.0 - Authenticated Blind SQL Injection via order_col Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47872. PoCs published by Piyush Patil.
AI-analyzed exploit summary This is a writeup describing a blind SQL injection vulnerability in SEO Panel 4.8.0 via the 'order_col' parameter. It provides steps to exploit the vulnerability using sqlmap but does not include functional exploit code.
Description
SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.
Exploits (1)
This is a writeup describing a blind SQL injection vulnerability in SEO Panel 4.8.0 via the 'order_col' parameter. It provides steps to exploit the vulnerability using sqlmap but does not include functional exploit code.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N