WordPress 的 FluentCRM Pro 插件(集电子邮件通讯、自动化、电子邮件营销、电子邮件活动、落地页捕获、潜在客户管理和客户关系管理解决方案于一体)在所有版本至 3.1.12 版本均存在 SQL 注入漏洞。该漏洞源于对用户提供的参数缺乏充分的转义处理,以及对现有 SQL 查询语句缺乏足够的预处理措施。这使得具备作者级(Author)及以上权限的已认证攻击者能够在已有的 SQL 查询中注入额外的 SQL 查询语句,从而可能从数据库中提取敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FluentCRM | FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | ≤ 3.1.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FluentCRM | FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | 0 ~ 3.1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet