8.8
CVE-2023-0098
- EPSS 0.94%
- Veröffentlicht 13.02.2023 15:15:20
- Zuletzt bearbeitet 21.03.2025 20:15:14
- CVE-Watchlists
- Unerledigt
Simple URLs < 115 - Subscriber+ SQLi
Simple URLs <= 114 - Authenticated (Subscriber+) SQL Injection
The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.
Mögliche Gegenmaßnahme
Lasso Lite – Affiliate Link Manager & Product Displays: Update to version 115, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Getlasso ≫ Simple Urls SwPlatformwordpress Version < 115
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Lasso Lite – Affiliate Link Manager & Product Displays
Version
*-114
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.94% | 0.564 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
https://wpscan.com/vulnerability/db0b3275-40df-404e-aa8d-53558f0122d8
https://www.wordfence.com/threat-intel/vulnerabilities/id/1644c2c3-11fa-48d6-ad99-416f27df4483