Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfrh-jg7v-x9p3

Опубликовано: 30 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

EPSS

Процентиль: 92%
0.08064
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
больше 2 лет назад

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

EPSS

Процентиль: 92%
0.08064
Низкий

7.2 High

CVSS3

Дефекты

CWE-89