Asgaros Forum < 1.15.13 - Unauthenticated SQL Injection
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 13%
from disclosure to weapon
Published on NVDNov 8
VulnCheck+1307d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue
Affected products
Unknown · Asgaros Forum