vendor:
WP Symposium
by:
dxw
6.4
CVSS
MEDIUM
Blind SQL Injection
89
CWE
Product Name: WP Symposium
Affected Version From: 15.1
Affected Version To: 15.7
Patch Exists: YES
Related CWE: Awaiting assignment
CPE: a:wordpress:wp_symposium
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Blind SQL Injection in WP Symposium allows unauthenticated attackers to access sensitive data
An unauthenticated user can run blind sql injection of the site and extract password hashes and other information from the database.
Mitigation:
Upgrade to version 15.8 or later