Fiche vulnérabilité
CVE-2022-1023 : faille élevée Unknown Podcast Importer SecondLine (CVSS 7.2)
Description
The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
En bref
- Sévérité
- Élevée (CVSS 7.2)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 11 avr. 2022
- Dernière mise à jour
- 2 août 2024
Produits concernés
- Unknown Podcast Importer SecondLine