The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4420 | The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internet-formation
Internet-formation wp-advanced-search |
|
| CPEs | cpe:2.3:a:internet-formation:wp-advanced-search:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wp-advanced-search Project
Wp-advanced-search Project wp-advanced-search |
Internet-formation
Internet-formation wp-advanced-search |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:48:58.138Z
Reserved: 2020-04-23T00:00:00
Link: CVE-2020-12104
No data.
Status : Modified
Published: 2020-05-05T15:15:12.420
Modified: 2024-11-21T04:59:15.183
Link: CVE-2020-12104
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD