CVE-2023-0279
27.02.2023, 16:15
The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.Enginsight
Vendor | Product | Version |
---|---|---|
media_library_assistant_project | media_library_assistant | 𝑥 < 3.06 |
𝑥
= Vulnerable software versions