Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m93-8pm8-gqxj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

EPSS

Процентиль: 98%
0.53132
Средний

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

EPSS

Процентиль: 98%
0.53132
Средний

Дефекты

CWE-89