Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS04N2ZnLTl4NXctajNybc4AA371
MainWP Dashboard SQL Command Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.
Permalink: https://github.com/advisories/GHSA-87fg-9x5w-j3rmJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04N2ZnLTl4NXctajNybc4AA371
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 12 months ago
Updated: 11 months ago
CVSS Score: 7.6
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Identifiers: GHSA-87fg-9x5w-j3rm, CVE-2023-38519
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-38519
- https://patchstack.com/database/vulnerability/mainwp/wordpress-mainwp-plugin-4-4-3-3-sql-injection-vulnerability?_s_id=cve
- https://github.com/mainwp/mainwp/commit/8df951c0e8b2c2646cc57fc66b00767551cac400
- https://github.com/advisories/GHSA-87fg-9x5w-j3rm
Blast Radius: 1.0
Affected Packages
packagist:mainwp/mainwp
Dependent packages: 0Dependent repositories: 0
Downloads: 122 total
Affected Version Ranges: <= 4.4.3.3
Fixed in: 4.4.3.4
All affected versions:
All unaffected versions: 4.0.4, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 4.1.7, 4.1.8, 4.1.9, 4.1.10, 4.1.11, 4.2.1, 4.2.3, 4.2.4, 4.2.6, 4.2.7