8.8

CVE-2023-0234

Exploit

SiteGround Security < 1.3.1 - Admin+ SQLi

SiteGround Security <= 1.3.0 - Authenticated (Administrator+) SQL Injection

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.
Mögliche Gegenmaßnahme
Security Optimizer – The All-In-One Protection Plugin: Update to version 1.3.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SitegroundSiteground Security SwPlatformwordpress Version < 1.3.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Security Optimizer – The All-In-One Protection Plugin
Version *-1.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 17.99% 0.968
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/namah-age/CVEs/blob/master/1.md
Third Party Advisory
https://wpscan.com/vulnerability/acf3e369-1290-4b3f-83bf-2209b9dd06e1
Third Party Advisory
Exploit
https://www.siteground.com/viewtos/responsible_disclosure_policy?scid=4&lang=en
Issue Tracking
https://www.wordfence.com/threat-intel/vulnerabilities/id/2af996d2-7430-4367-8fd9-212df6106fb0
Third Party Advisory