CVE-2023-6035

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGH
EPSS
0.4%
top 41.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11

Description

The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5unknown/eazydocs< 2.3.4

🔴Vulnerability Details

2
CVEList
EazyDocs < 2.3.4 - Subscriber + SQLi2023-12-11
GHSA
GHSA-gf95-rw86-w2vf: The EazyDocs WordPress plugin before 22023-12-11
CVE-2023-6035 (HIGH CVSS 8.8) | The EazyDocs WordPress plugin befor | cvebase.io