Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xcq-547q-fvjw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

EPSS

Процентиль: 75%
0.00912
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

EPSS

Процентиль: 75%
0.00912
Низкий

Дефекты

CWE-89