Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp4m-cvm9-gmvp

Опубликовано: 30 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

EPSS

Процентиль: 97%
0.39009
Средний

9.1 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

EPSS

Процентиль: 97%
0.39009
Средний

9.1 Critical

CVSS3

Дефекты

CWE-89