Описание
The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.6.5 (исключая)
cpe:2.3:a:export_users_with_meta_project:export_users_with_meta:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 76%
0.00974
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.
EPSS
Процентиль: 76%
0.00974
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89