Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmg5-2fm4-j8w9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.

The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.

EPSS

Процентиль: 68%
0.00567
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.6
nvd
больше 4 лет назад

The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.

EPSS

Процентиль: 68%
0.00567
Низкий

Дефекты

CWE-89