CVE-2023-5203
Last modified
CVE-2023-5203 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.. EPSS estimates a 2.22% chance of exploitation in the next 30 days.
Description
The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Swit | Wp Sessions Time Monitoring Full Automatic | < 1.0.9 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5203?
How severe is CVE-2023-5203?
How do I fix CVE-2023-5203?
Are you affected by CVE-2023-5203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
