Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr3p-gm2p-7rx5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

EPSS

Процентиль: 98%
0.58256
Средний

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

EPSS

Процентиль: 98%
0.58256
Средний

Дефекты

CWE-89