WordPress Amelia是WordPress基金会的一个WordPress预约与活动预订插件。 WordPress Amelia 2.4.3及之前版本存在SQL注入漏洞,该漏洞源于用户提供的参数转义不足以及对现有SQL查询缺乏充分准备,可能导致通过wpamelia-manager角色的认证攻击者将额外的SQL查询追加到现有查询中,从而从数据库获取敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| melograno | Booking for Appointments and Events Calendar – Amelia | ≤ 2.4.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| melograno | Booking for Appointments and Events Calendar – Amelia | 0 ~ 2.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet