Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qv2-4g99-78c9

Опубликовано: 19 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

EPSS

Процентиль: 99%
0.7029
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

EPSS

Процентиль: 99%
0.7029
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89