Tax Service Electronic HDM < 1.2.1 - Unauthenticated Arbitrary SQL Execution
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected products
Unknown · TAX SERVICE Electronic HDM