Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 3 min 106 bronnen 1 kritiek 1 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-5185

MEDIUM · 6.0 CVSS Gepubliceerd: CWE-89

Beschrijving

SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor privileges to execute arbitrary SQL commands via the quote parameter in an edit action in the quartz/quote_form.php page to wp-admin/edit.php.

Vendors

Quartz Plugin Project

Affected products

Quartz Plugin

References