SQL Injection Vulnerability in Cardoza WordPress Poll Plugin by Vinoj Cardoza
CVE-2020-24315
7.5HIGH
Summary
The Cardoza WordPress Poll Plugin, up to version 36, is susceptible to an SQL injection vulnerability. This issue arises from the inadequate escaping of user inputs in the pollid POST parameter. Malicious actors can exploit this flaw by submitting specially crafted SQL statements, granting them unauthorized access and allowing the potential dumping of the entire database. Proper input validation and escaping measures are crucial for safeguarding against such vulnerabilities.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved