Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrj8-8872-rq8p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

EPSS

Процентиль: 99%
0.72516
Высокий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

EPSS

Процентиль: 99%
0.72516
Высокий

Дефекты

CWE-89