vendor:
SEO Panel
by:
nu11secur1ty
7.2
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: SEO Panel
Affected Version From: 4.8.2000
Affected Version To: 4.8.2000
Patch Exists: NO
Related CWE: CVE-2021-28419
CPE: a:seopanel:seopanel:4.8.0
Tags: cve,cve2021,sqli,seopanel,auth,packetstorm
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 3, 'verified': True, 'vendor': 'seopanel', 'product': 'seo_panel'}
Platforms Tested:
2021
SEO Panel 4.8.0 – ‘order_col’ Blind SQL Injection (2)
This exploit allows an attacker to perform a blind SQL injection attack in SEO Panel version 4.8.0. By manipulating the 'order_col' parameter in the archive.php page, an attacker can execute arbitrary SQL queries.
Mitigation:
Update to a patched version of SEO Panel or apply the vendor's recommended fixes.