PT-2019-12710 · WordPress · Wp Booking System
CVE-2019-12239
·
Publicado
2019-05-20
·
Atualizado
2023-02-24
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Booking System plugin version 1.5.1
Description
The issue is related to the lack of CSRF protection, which can allow attackers to exploit certain SQL injection issues that require administrative access.
Recommendations
For WP Booking System plugin version 1.5.1, consider implementing CSRF protection measures to prevent exploitation of SQL injection issues until a patch is available.
Exploit
Correção
CSRF
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wp Booking System