Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7pwr-5hfg-qhv4

Опубликовано: 25 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection

The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection

EPSS

Процентиль: 75%
0.00903
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
около 4 лет назад

The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection

EPSS

Процентиль: 75%
0.00903
Низкий

Дефекты

CWE-89