Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mchv-2c9q-xfg9

Опубликовано: 02 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

EPSS

Процентиль: 99%
0.85374
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

EPSS

Процентиль: 99%
0.85374
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89