CVE-2023-2719
19.06.2023, 11:15
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.Enginsight
Vendor | Product | Version |
---|---|---|
supportcandy | supportcandy | 𝑥 < 3.1.7 |
𝑥
= Vulnerable software versions