Beveiligingsadvies

CVE-2022-0817

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-05-09 16:50:34
Laatst bijgewerkt 2024-08-02 23:40:04
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users