CVE-2022-3142: NEX-Forms Plugin < 7.9.7 - SQL Injection

CVE-2022-3142: NEX-Forms Plugin < 7.9.7 - SQL Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2022-3142: NEX-Forms Plugin < 7.9.7 - SQL Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-3142: NEX-Forms Plugin < 7.9.7 – SQL Injection

漏洞描述

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享