PT-2023-25958 · Unknown · Wp Page Builder
David Manuel Herrera Rodríguez
·
Publicado
2023-07-18
·
Atualizado
2023-07-27
·
CVE-2023-3743
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ap Page Builder versions prior to 1.7.8.2
Description
The issue allows a remote attacker to send a specially crafted SQL query to the
product one img parameter to retrieve the information stored in the database.Recommendations
For versions prior to 1.7.8.2, update to version 1.7.8.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
product one img parameter to minimize the risk of exploitation.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wp Page Builder