The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Internet-formation
Internet-formation wp-advanced-search |
|
CPEs | cpe:2.3:a:internet-formation:wp-advanced-search:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wp-advanced-search Project
Wp-advanced-search Project wp-advanced-search |
Internet-formation
Internet-formation wp-advanced-search |
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-05-05T14:17:40
Updated: 2024-08-04T11:48:58.138Z
Reserved: 2020-04-23T00:00:00
Link: CVE-2020-12104
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-05T15:15:12.420
Modified: 2024-11-21T04:59:15.183
Link: CVE-2020-12104
Redhat
No data.