The Track The Click WordPress plugin... CVE-2023-5041

- AV AC AU C I A
发布: 2024-01-17
修订: 2024-01-24

The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息