CVE-2021-24442 Scanner
Targets the 'date_answers[]' POST parameter in the Polls Widget plugin. An attacker can inject arbitrary SQL to extract or modify database contents.
Used 3k times · 4.3k assets checked · domain, ipv4, subdomain
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks
Targets the 'date_answers[]' POST parameter in the Polls Widget plugin. An attacker can inject arbitrary SQL to extract or modify database contents.
Used 3k times · 4.3k assets checked · domain, ipv4, subdomain
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →