关键信息 漏洞名称 SEO Panel < 4.9.0 - 'order_col' Blind SQL Injection 严重程度 HIGH 发布日期 January 21, 2026 影响版本 SEO Panel 4.8.0 CVE ID CVE-2021-47872 CWE ID CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVSS V4 Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N 参考链接 ExploitDB-49666 Official SEO Panel Homepage SEO Panel 4.9.0 Release GitHub Issue #209 发现者 Piyush Patil 漏洞描述 SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.