摘要:
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
安全等级: Low
公告ID: KylinSec-SA-2022-2530
发布日期: 2022年10月24日
关联CVE: CVE-2022-2840
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2022-2840 | KY3.4-4A | zephyr | Unaffected |
CVE-2022-2840 | KY3.4-5 | zephyr | Unaffected |
CVE-2022-2840 | KY3.5.1 | zephyr | Unaffected |