CVE-2023-2805
19.06.2023, 11:15
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.Enginsight
Vendor | Product | Version |
---|---|---|
supportcandy | supportcandy | 𝑥 < 3.1.7 |
𝑥
= Vulnerable software versions