WordPress Image Uploader for Welcart是WordPress基金会开源的一个为电商平台提供图片上传功能的组件。 WordPress Image Uploader for Welcart 1.4.6及之前版本存在SQL注入漏洞,该漏洞源于对用户提供的post_title参数清理不充分以及对现有SQL查询准备不足,可能导致SQL注入,经过身份验证的攻击者可利用该漏洞提取数据库中的敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| fishpie | Image Uploader for Welcart | ≤ 1.4.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| fishpie | Image Uploader for Welcart | 0 ~ 1.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet