Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j39-64q5-rjfv

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

EPSS

Процентиль: 77%
0.01821
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

EPSS

Процентиль: 77%
0.01821
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89