漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter
Vulnerability Description
The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic quotes protection, followed by direct concatenation into a SQL query without proper escaping or prepared statements in the qa_user_profile_card() function. This makes it possible for unauthenticated attackers to append additional SQL queries into existing queries, which can be used to extract sensitive information from the database.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
WordPress Question Answer SQL注入漏洞
Vulnerability Description
WordPress Question Answer是WordPress基金会开源的一款问答功能的CMS插件。 WordPress Question Answer 1.2.73及之前版本存在SQL注入漏洞,该漏洞源于通过'id' GET参数的用户输入清理不充分,结合wp_unslash()移除魔法引号保护,直接拼接到SQL查询中,导致未经身份验证的攻击者能够追加SQL查询,从而提取数据库敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A