vendor:
Copperleaf Photolog
by:
kaMtiEz
5.5
CVSS
MEDIUM
SQL injection
89
CWE
Product Name: Copperleaf Photolog
Affected Version From: 0.16
Affected Version To: Lower versions may also be affected
Patch Exists: NO
Related CWE:
CPE: a:copperleaf_project:copperleaf_photolog
Platforms Tested:
2009
WordPress Copperleaf Photolog SQL injection
The WordPress Copperleaf Photolog plugin is vulnerable to SQL injection. The vulnerability allows an attacker to execute arbitrary SQL queries in the context of the application's database. By exploiting this vulnerability, an attacker can potentially gain unauthorized access to sensitive information or modify the database.
Mitigation:
The vendor has not provided a fix for this vulnerability. It is recommended to disable or remove the vulnerable plugin until a patch is available.