The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/13a196ba-49c7-4575-9a49-3ef9eb2348f3 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-11-06 21:15
Updated : 2023-11-14 15:33
NVD link : CVE-2023-5082
Mitre link : CVE-2023-5082
CVE.ORG link : CVE-2023-5082
JSON object : View
Products Affected
click5interactive
- sitemap_by_click5
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')