Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-725x-5972-gm8m

Опубликовано: 20 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

EPSS

Процентиль: 84%
0.02149
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

EPSS

Процентиль: 84%
0.02149
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89