Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgvw-rx29-9j22

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

EPSS

Процентиль: 99%
0.72898
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

EPSS

Процентиль: 99%
0.72898
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-89