SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  WordPress plugin NEX-Forms SQL Injection

Category: WEB-ATTACKS      

The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.


Relevant Information