PT-2017-11014 · Unknown · Add-Edit-Delete-Listing-For-Member-Module
Larry W. Cashdollar
+1
·
Published
2017-09-14
·
Updated
2017-09-21
·
CVE-2017-1002025
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
add-edit-delete-listing-for-member-module version 1.0
Description
The issue arises from the plugin author's failure to sanitize user-supplied input via the
$act variable before passing it into an SQL statement, potentially leading to SQL injection.Recommendations
For version 1.0, ensure proper sanitization of user input, specifically the
$act variable, before it is used in SQL statements to prevent injection attacks. Consider validating and escaping user input to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Add-Edit-Delete-Listing-For-Member-Module