WordPress Plugin Vulnerabilities
Ultimate Product Catalogue <= 4.2.2 - Authenticated SQL Injection
Description
Type user access: subscriber upwards.
$_POST[‘CatID’] is not escaped.
File / Code:
Path: /wp-content/plugins/ultimate-product-catalogue/Functions/Process_Ajax.php
Proof of Concept
Affects Plugins
References
Classification
Type
SQLI
OWASP top 10
CWE
Miscellaneous
Submitter
Lenon Leite / Log.pt
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2017-06-27 (about 8 years ago)
Added
2017-06-28 (about 8 years ago)
Last Updated
2019-11-01 (about 6 years ago)