PT-2017-16891 · WordPress · Mail Masta

Hanley Shun

·

Published

2017-02-21

·

Updated

2019-03-13

·

CVE-2017-6095

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mail Masta plugin version 1.0
Description A SQL injection issue was discovered in the Mail Masta plugin for WordPress. This issue affects the /inc/lists/csvexport.php endpoint, specifically with the list id parameter, and can be exploited without authentication.
Recommendations For Mail Masta plugin version 1.0, consider disabling access to the /inc/lists/csvexport.php endpoint until a patch is available, or restrict the use of the list id parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6095

Affected Products

Mail Masta