Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhcq-6xcp-843h

Опубликовано: 08 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

EPSS

Процентиль: 99%
0.88588
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

EPSS

Процентиль: 99%
0.88588
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89