Aller au contenu

Fiche vulnérabilité

CVE-2022-1023 : faille élevée Unknown Podcast Importer SecondLine (CVSS 7.2)

Description

The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
11 avr. 2022
Dernière mise à jour
2 août 2024

Produits concernés

  • Unknown Podcast Importer SecondLine

Références

Rechercher une autre vulnérabilité dans la base CVE