WordPress 插件 Beaver Builder Page Builder(一款拖放式网站构建器插件)在所有版本直至包括 2.11.0.5 中,存在一处盲注型 SQL 注入漏洞。该漏洞源于对“fields[][value]”参数的用户输入缺乏充分的转义处理,以及对现有 SQL 查询缺乏足够的预处理。这使得具备 Contributor(贡献者)及以上权限的攻击者,能够将额外的 SQL 查询语句注入到已有的查询中,从而从数据库中窃取敏感信息。 受影响的 vulnerable get_autosuggest_val
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | 0 ~ 2.11.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet