Описание
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).
Ссылки
- ExploitThird Party Advisory
- PatchVendor Advisory
- ExploitVendor Advisory
- ExploitThird Party Advisory
- PatchVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.5.3 (исключая)
cpe:2.3:a:aioseo:all_in_one_seo:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 73%
0.00792
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
около 4 лет назад
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).
EPSS
Процентиль: 73%
0.00792
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-89