PT-2023-9948 · Unknown · Hd Flv Player Plugin

Published

2023-04-09

·

Updated

2024-05-17

·

CVE-2012-10011

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HD FLV Player Plugin versions up to 1.7
Description A critical issue has been found in the HD FLV Player Plugin, affecting the function hd add media/hd update media of the file functions.php. The manipulation of the argument name leads to SQL injection. This issue can be exploited remotely.
Recommendations For HD FLV Player Plugin versions up to 1.7, upgrade to version 1.8 to address this issue. As a temporary workaround, consider restricting access to the hd add media/hd update media function in the functions.php file until the upgrade is applied.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2012-10011

Affected Products

Hd Flv Player Plugin