CVE-2023-0768
Avirato hotels online booking engine <= 5.0.5 - Subscriber+ SQLi
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
08 may 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Unknown · Avirato hotels online booking engine¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →