vendor:
Social Share Buttons
by:
nu11secur1ty
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Social Share Buttons
Affected Version From: Social Share Buttons-2.2.3
Affected Version To: WordPress-6.0.2
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2022
Social-Share-Buttons v2.2.3 – SQL Injection
The `project_id` parameter from the Social Share Buttons-2.2.3 on the WordPress-6.0.2 system appears to be vulnerable to SQL injection attacks. The malicious user can dump-steal the database, from this system and he can use it for very malicious purposes. WARNING: The attacker can retrieve all-database from this system! NOTE: The users of this system are NOT protected, this SQL vulnerability is CRITICAL!
Mitigation:
The users of this system should be protected from SQL injection attacks.