Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2cr-m5mp-6v2m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

EPSS

Процентиль: 98%
0.51483
Средний

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

EPSS

Процентиль: 98%
0.51483
Средний

Дефекты

CWE-89