ZeroHour

CVE-2017-18570

CVSS 3.0
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

Vendors
cformsii project
Products
cformsii
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.