WordPress 插件 SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent 在所有不超过 3.5.3 的版本中存在基于时间的 SQL 注入漏洞,原因是用户提供的 参数缺乏充分的转义处理,且对现有 SQL 查询缺乏足够的预处理。这使得具备认证权限的攻击者能够注入额外的 SQL 查询语句,从而从数据库中窃取敏感信息。成功利用该漏洞需要攻击者同时满足以下条件:持有 WordPress 订阅者(Subscriber)或更高权限的角色,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| psmplugins | SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent | 0 ~ 3.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet