PT-2017-13674 · WordPress · Event-Espresso-Free
Publicado
2017-09-27
·
Atualizado
2017-10-06
·
CVE-2017-14760
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
event-espresso-free plugin version 3.1.37.12.L
Description
A SQL Injection issue exists in the event-espresso-free plugin for WordPress. The issue is related to the
recurrence id parameter in the /includes/event-management/index.php file, which is accessible via the /wp-admin/admin.php endpoint.Recommendations
For event-espresso-free plugin version 3.1.37.12.L, consider restricting access to the
/wp-admin/admin.php endpoint until a patch is available, and avoid using the recurrence id parameter to minimize the risk of exploitation.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Event-Espresso-Free