Описание
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.1 (включая)
cpe:2.3:a:sendit_project:sendit:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 68%
0.00567
Низкий
6.6 Medium
CVSS3
6 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.
EPSS
Процентиль: 68%
0.00567
Низкий
6.6 Medium
CVSS3
6 Medium
CVSS2
Дефекты
CWE-89