Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injection
52Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actepss 47%
de la publicación al arma
Publicada en NVD12 jul
VulnCheck+1425d
probabilidad de explotación
47%top 1% de las CVE
explotación observada
síVulnCheck
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks
Productos afectados
wpdevart · Poll, Survey, Questionnaire and Voting system