Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pchr-vw8h-5h7w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

EPSS

Процентиль: 72%
0.00703
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

EPSS

Процентиль: 72%
0.00703
Низкий

Дефекты

CWE-89