Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37j5-fv6r-vwgr

Опубликовано: 13 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

EPSS

Процентиль: 69%
0.00607
Низкий

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

EPSS

Процентиль: 69%
0.00607
Низкий

8.8 High

CVSS3

Дефекты

CWE-89