WordPress Icegram Mailer是WordPress基金会的一款电子邮件营销工具。 WordPress Icegram Mailer 1.0.12及之前版本存在SQL注入漏洞,该漏洞源于对'fields'参数的用户输入转义不足且未对现有SQL查询进行充分预处理,在Icegram_Mailer_Logs_Table::get_logs()函数中,可能导致具有管理员及以上权限的已认证攻击者向现有查询追加额外SQL查询,从而提取数据库中的敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| icegram | Icegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logs | ≤ 1.0.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| icegram | Icegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logs | 0 ~ 1.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet