Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7gp5-vwvv-wq8v

Опубликовано: 15 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

EPSS

Процентиль: 98%
0.47252
Средний

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

EPSS

Процентиль: 98%
0.47252
Средний

9.8 Critical

CVSS3

Дефекты

CWE-89