RSS   Vulnerabilities for 'Registrationmagic'   RSS

2022-03-07
 
CVE-2022-0420

CWE-89
 

 
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

 
2022-02-01
 
CVE-2021-24648

CWE-79
 

 
The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting

 
2022-01-10
 
CVE-2021-24862

CWE-89
 

 
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

 

 >>> Vendor: Metagauss 4 Products
Profilegrid
Registrationmagic
Download plugin
Leadmagic


Copyright 2024, cxsecurity.com

 

Back to Top