Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7r2-qc5v-3hvm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.

EPSS

Процентиль: 65%
0.00501
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.

EPSS

Процентиль: 65%
0.00501
Низкий

Дефекты

CWE-89