OSV 1.4.0 · unreviewed · 修改于 2021-12-01 08:00
发布时间
2021-11-30 08:00
GitHub 审查时间
—
NVD 发布时间
2021-11-29 17:15
源文件
advisories/unreviewed/2021/11/GHSA-986q-37xh-j7h2/GHSA-986q-37xh-j7h2.json
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address
该公告没有提供结构化的受影响软件包信息。