Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j39-64q5-rjfv

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

EPSS

Процентиль: 75%
0.00868
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

EPSS

Процентиль: 75%
0.00868
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89