momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2023-3197: WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection

CVE: CVE-2023-3197
CNVD: 暂无
CNNVD: 暂无
漏洞类型: SQL注入
漏洞等级: 严重
年份: 2026
POC_ID: 暂无
漏洞描述
MStore API plugin for WordPress up to version 4.0.1 contains an unauthenticated blind SQL injection caused by insufficient escaping of 'id' parameter in SQL queries, letting attackers execute arbitrary SQL commands without authentication, exploit requires sending crafted requests with malicious 'id' parameter. [已公开] id: CVE-2023-3197 info: name: WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection author: Shivam Kamboj severity: critical description: | MStore API plugin for WordPress up to version 4.0.1 contains an unauthenticated blind SQL injection caused by insufficient escaping of 'id' parameter in SQL queries, letting attackers execute arbitrary SQL commands without authentication, exploit requires sending crafted requests with malicious 'id' parameter. impact: | Attackers can extract sensitive database information, potentially leading to data breach and compromise of the website. remediation: | Update to the latest version of the plugin where the vulnerability is fixed. reference: - https://nvd.nist.gov/vuln/detail/CVE-2023-3197 - https://www.wordfence.com/threat-intel/vulnerabilities/id/30aab1af-a78f-4bac-b3c5-30ea854ccef7?source=cve metadata: verified: true max-req
影响范围
未知
漏洞详情
登录后可查看漏洞详情。请先 登录注册
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无