vendor:
WP Symposium
by:
Kacper Szurek
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: WP Symposium
Affected Version From: 14.1
Affected Version To: 14.1
Patch Exists: YES
Related CWE: CVE-2014-8810
CPE: a:wp_symposium:wp_symposium:14.10
Platforms Tested:
2014
WP Symposium 14.10 SQL Injection
The 'tray' parameter in the wp-symposium/ajax/mail_functions.php file is not properly escaped, leading to a SQL Injection vulnerability. An attacker can exploit this vulnerability to execute arbitrary SQL queries.
Mitigation:
Update to version 14.11