Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xgj7-47qp-p88h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

EPSS

Процентиль: 72%
0.01517
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

EPSS

Процентиль: 72%
0.01517
Низкий

Дефекты

CWE-89