Description
The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57422 | The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it. |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-26T21:19:03.513Z
Reserved: 2023-09-19T21:13:44.430Z
Link: CVE-2023-5082
Updated: 2024-08-02T07:44:53.677Z
Status : Modified
Published: 2023-11-06T21:15:09.517
Modified: 2025-02-26T22:15:13.003
Link: CVE-2023-5082
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD