Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f337-c24p-gw2w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a shortcode_products_table action to wp-admin/admin-ajax.php.

SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a shortcode_products_table action to wp-admin/admin-ajax.php.

EPSS

Процентиль: 88%
0.03695
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
около 11 лет назад

SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a shortcode_products_table action to wp-admin/admin-ajax.php.

EPSS

Процентиль: 88%
0.03695
Низкий

Дефекты

CWE-89