The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-08-14T19:10:19.283Z

Updated: 2024-01-16T15:54:04.428Z

Reserved: 2023-06-27T17:40:30.280Z


Link: CVE-2023-3435

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-08-14T20:15:11.747

Modified: 2023-11-07T04:18:43.933


Link: CVE-2023-3435

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.