WordPress Plugin Vulnerabilities
Freshmail for WordPress < 1.6 - Unauthenticated SQL Injection
Description
There is a unauthenticated SQL injection vulnerability in the "Subscribe to
our newsletter" formularies showed to the web visitors in the POST parameter fm_form_id.
Proof of Concept
Affects Plugins
References
Exploitdb
Classification
Type
SQLI
OWASP top 10
CWE
Miscellaneous
Submitter
Felipe Molina
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2015-05-06 (about 10 years ago)
Added
2015-05-08 (about 10 years ago)
Last Updated
2019-10-21 (about 6 years ago)