Описание
A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.
Ссылки
- ExploitThird Party Advisory
- Product
- Product
- ExploitThird Party Advisory
- Product
- Product
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:economizzer:economizzer:0.9:beta1:*:*:*:wordpress:*:*
cpe:2.3:a:economizzer:economizzer:april_2023:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 37%
0.00153
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 9.8
github
больше 2 лет назад
A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.
EPSS
Процентиль: 37%
0.00153
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89