OSV 1.4.0 · unreviewed · 修改于 2021-12-28 08:01
发布时间
2021-12-22 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-21 17:15
源文件
advisories/unreviewed/2021/12/GHSA-2hw2-7jq8-w9vp/GHSA-2hw2-7jq8-w9vp.json
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
该公告没有提供结构化的受影响软件包信息。