Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id
Vulnerability Description
The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Library Management System SQL注入漏洞
Vulnerability Description
Online Web Tutor Library Management System是Online Web Tutor团队的一款图书馆管理软件。 WordPress Library Management System 3.5.8之前版本存在SQL注入漏洞,该漏洞源于未清理和转义用户提供的参数,允许未经身份验证的攻击者进行SQL注入并从数据库中提取任意数据,包括用户密码哈希。
CVSS Information
N/A
Vulnerability Type
N/A