Логотип exploitDog
bind:CVE-2021-24750
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24750

Количество 2

Количество 2

nvd логотип

CVE-2021-24750

около 4 лет назад

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-p934-c89c-rc2m

около 4 лет назад

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24750

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVSS3: 8.8
70%
Средний
около 4 лет назад
github логотип
GHSA-p934-c89c-rc2m

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVSS3: 8.8
70%
Средний
около 4 лет назад

Уязвимостей на страницу