vendor:
Elementor Website Builder
by:
E1.Coders
6.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Elementor Website Builder
Affected Version From: 3.12.2001
Affected Version To: 3.12.2002
Patch Exists: YES
Related CWE: CVE-2023-0329
CPE: a:elementor:elementor_website_builder:3.12.1
Platforms Tested:
2023
Elementor Website Builder SQL Injection Vulnerability
An attacker can exploit a SQL injection vulnerability in Elementor Website Builder version less than 3.12.2 by sending a malicious payload through the 'Replace URL' feature. By executing a specific SQL command, the attacker can make the server hang for 2 seconds, indicating a successful injection.
Mitigation:
To mitigate this vulnerability, it is recommended to update Elementor Website Builder to version 3.12.2 or higher.