8.8
CVE-2023-0234
- EPSS 17.99%
- Veröffentlicht 06.02.2023 20:15:14
- Zuletzt bearbeitet 25.03.2025 19:15:40
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
SiteGround Security < 1.3.1 - Admin+ SQLi
SiteGround Security <= 1.3.0 - Authenticated (Administrator+) SQL Injection
The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.
Mögliche Gegenmaßnahme
Security Optimizer – The All-In-One Protection Plugin: Update to version 1.3.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siteground ≫ Siteground Security SwPlatformwordpress Version < 1.3.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Security Optimizer – The All-In-One Protection Plugin
Version
*-1.3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 17.99% | 0.968 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://github.com/namah-age/CVEs/blob/master/1.md
https://wpscan.com/vulnerability/acf3e369-1290-4b3f-83bf-2209b9dd06e1
https://www.siteground.com/viewtos/responsible_disclosure_policy?scid=4&lang=en
https://www.wordfence.com/threat-intel/vulnerabilities/id/2af996d2-7430-4367-8fd9-212df6106fb0