Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x469-5gjm-mqfr

Опубликовано: 12 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

EPSS

Процентиль: 98%
0.58137
Средний

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

EPSS

Процентиль: 98%
0.58137
Средний

9.8 Critical

CVSS3

Дефекты

CWE-89