Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxph-v45w-r6xc

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

EPSS

Процентиль: 90%
0.06008
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

EPSS

Процентиль: 90%
0.06008
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89