vendor:
mooSocial Store Plugin
by:
Andrea Bocchetti
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: mooSocial Store Plugin
Affected Version From: all versions
Affected Version To: 2.6
Patch Exists: YES
Related CWE:
CPE: a:moosocial:mooSocial_Store_Plugin:2.6
Platforms Tested: Ubuntu
2018
mooSocial Store Plugin 2.6 – SQL Injection
mooSocial Store Plugin is affected by Blind SQL Injection in the product parameter used with URL Rewrite
Mitigation:
Upgrade to patched version 2.7