WordPress 插件 Smart Marketing SMS and Newsletters Forms 在所有版本(包括 5.1.24 及更早版本)中存在通用型 SQL 注入漏洞,原因是插件对用户提供的参数(参数名)缺乏充分转义,且现有 SQL 查询未进行充分的预处理。 这使得具有 subscriber 级别及以上权限 的已认证攻击者能够向现有 SQL 查询中追加额外的 SQL 语句,从而从数据库中提取敏感信息。 成功利用该漏洞需要同时满足以下条件: 1. 插件的同步功能已启用( 为真); 2. 为真值。 这
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| egoi | Smart Marketing SMS and Newsletters Forms | 0 ~ 5.1.24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet