RSS   Vulnerabilities for 'Wordpress poll'   RSS

2020-08-26
 
CVE-2020-24315

CWE-89
 

 
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.

 


Copyright 2024, cxsecurity.com

 

Back to Top