Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7vhh-8w84-5hwq

Опубликовано: 10 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.4

Описание

The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.

The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.

EPSS

Процентиль: 56%
0.00332
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.4
nvd
больше 1 года назад

The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.

EPSS

Процентиль: 56%
0.00332
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-89