ZeroHour

CVE-2018-1002000

PoC ×2
CVSS 3.0
7.2 high
EPSS
4%p91
Published
()
Modified
Description

There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

Vendors
kibokolabs
Products
arigato autoresponder and newsletter
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.