WordPress Plugin Vulnerabilities

Hermit <= 3.1.6 - Unauthenticated SQLi

Description

The plugin does not sanitise and escape the id parameter before using it in a SQL statement, leading to a SQL injection

Affects Plugins

No known fix

References

Classification

Type
SQLI
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Lenon Leite
Verified
No

Timeline

Publicly Published
2022-04-28 (about 4 years ago)
Added
2022-04-28 (about 4 years ago)
Last Updated
2022-04-29 (about 4 years ago)

Other