PT-2023-16012 · WordPress · Simple Urls

·

CVE-2023-0098

·

Publicado

2023-02-13

·

Atualizado

2023-02-21

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple URLs WordPress plugin versions prior to 115
Description The issue concerns a SQL injection problem. It arises because the plugin does not properly escape certain parameters before using them in SQL statements for AJAX actions. These actions are accessible to any authenticated user, making the SQL injection exploitable by low-privilege users, such as subscribers.
Recommendations For versions prior to 115, update to version 115 or later to resolve the SQL injection issue. As a temporary workaround, consider restricting access to AJAX actions to higher-privileged users until the update can be applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-0098

Produtos afetados

Simple Urls