Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ccc5-p96c-p626

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

EPSS

Процентиль: 60%
0.00394
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

EPSS

Процентиль: 60%
0.00394
Низкий