CVE-2022-3981
12.12.2022, 18:15
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriberEnginsight
Vendor | Product | Version |
---|---|---|
icegram | email_subscribers_\&_newsletters | 𝑥 < 5.5.1 |
𝑥
= Vulnerable software versions