The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2023-05-02T07:05:01.073Z
Updated: 2025-01-30T14:23:35.538Z
Reserved: 2023-03-30T14:55:03.802Z
Link: CVE-2023-1730

Updated: 2024-08-02T05:57:24.977Z

Status : Modified
Published: 2023-05-02T08:15:10.267
Modified: 2025-01-30T15:15:13.767
Link: CVE-2023-1730

No data.