PT-2020-20135 · WordPress · Registrationmagic

Published

2020-03-12

·

Updated

2022-01-21

·

CVE-2020-8435

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions RegistrationMagic plugin version 4.6.0.0
Description An issue was discovered in the RegistrationMagic plugin for WordPress, where there is SQL injection via the rm analytics show form rm form id parameter.
Recommendations For RegistrationMagic plugin version 4.6.0.0, avoid using the rm form id parameter in the rm analytics show form until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8435

Affected Products

Registrationmagic