Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xgj7-47qp-p88h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

EPSS

Процентиль: 73%
0.00768
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

EPSS

Процентиль: 73%
0.00768
Низкий

Дефекты

CWE-89