Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-83g3-fg3c-hpxj

Опубликовано: 14 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

EPSS

Процентиль: 70%
0.00631
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

EPSS

Процентиль: 70%
0.00631
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89