Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vf3-j8cr-x4g6

Опубликовано: 20 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

EPSS

Процентиль: 99%
0.79212
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

EPSS

Процентиль: 99%
0.79212
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-89