Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv52-8ff7-g4jf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

EPSS

Процентиль: 67%
0.00532
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

EPSS

Процентиль: 67%
0.00532
Низкий

Дефекты

CWE-89