Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwrq-g8w9-vh68

Опубликовано: 24 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the txtsearch parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.

The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the txtsearch parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.

EPSS

Процентиль: 39%
0.0017
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 лет назад

The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.

EPSS

Процентиль: 39%
0.0017
Низкий

7.2 High

CVSS3

Дефекты

CWE-89