CVE-2023-2719
EUVD-2023-3418319.06.2023, 11:15
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| supportcandy | supportcandy | 𝑥 < 3.1.7 |
𝑥
= Vulnerable software versions