Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m38f-j4wj-5268

Опубликовано: 07 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

EPSS

Процентиль: 6%
0.00022
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
nvd
6 дней назад

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

EPSS

Процентиль: 6%
0.00022
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89