SEO Panel < 4.9.0 - 'order_col' Blind SQL Injection
Vulnerability Description
SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47872
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Piyush Patil
References
Affected Vendor
SEO Panel
View all reports →