Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v5rm-528g-7mvp

Опубликовано: 14 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

EPSS

Процентиль: 96%
0.21731
Средний

8.6 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 года назад

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

EPSS

Процентиль: 96%
0.21731
Средний

8.6 High

CVSS3

Дефекты

CWE-89