Описание
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitPatchThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2.5 (исключая)
cpe:2.3:a:zephyr-one:zephyr_project_manager:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 90%
0.05182
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
EPSS
Процентиль: 90%
0.05182
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89