Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c568-8x7p-64q6

Опубликовано: 26 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

EPSS

Процентиль: 93%
0.10394
Средний

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость плагина WP Sessions Time Monitoring Full Automatic системы управления содержимым сайта WordPress, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 93%
0.10394
Средний

7.5 High

CVSS3

Дефекты

CWE-89