Lucene search

K
wpvulndbWpvulndbWPVDB-ID:653EDD42-E34F-4BE1-A2F0-5814EDCD6994
HistoryMay 11, 2023 - 12:00 a.m.

Slimstat Analytics < 5.0.5 - Admin+ SQLi

2023-05-1100:00:00
wpscan.com
8
slimstat analytics
sql injection
admin privilege
software vulnerability

EPSS

0.001

Percentile

33.0%

The plugin does not sanitise and escape the misc[limit_results] parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

EPSS

0.001

Percentile

33.0%

Related for WPVDB-ID:653EDD42-E34F-4BE1-A2F0-5814EDCD6994