Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
6.15.12 (custom)
Credits
vtim | Patchstack Bug Bounty Program
References
patchstack.com/...16-2-sql-injection-vulnerability?_s_id=cve