OSV 1.4.0 · unreviewed · 修改于 2021-12-08 08:01
发布时间
2021-12-07 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-07 00:15
源文件
advisories/unreviewed/2021/12/GHSA-756m-jgjv-8g68/GHSA-756m-jgjv-8g68.json
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
该公告没有提供结构化的受影响软件包信息。