SQL Injection Vulnerability in DTracker WordPress Plugin by DTracker
CVE-2017-1002005
7.5HIGH
Summary
The DTracker WordPress plugin version 1.5 contains a vulnerability that permits SQL injection due to a lack of input sanitization in the delete.php file. Specifically, the contact_id variable is incorporated into an SQL query without proper sanitization, enabling malicious users to manipulate the SQL query. This flaw could allow for unauthorized access to sensitive information, making it crucial for users of the affected plugin to apply necessary updates and security measures.
Affected Version(s)
DTracker < 1.5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved