This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/6f3f460b-542a-4d32-8feb-afa1aef57e37 | Exploit |
Configurations
History
07 Nov 2023, 04:02
Type | Values Removed | Values Added |
---|---|---|
CWE |
08 Aug 2023, 11:45
Type | Values Removed | Values Added |
---|---|---|
First Time |
Riverside http Headers
Riverside |
|
CPE | cpe:2.3:a:riverside:http_headers:*:*:*:*:*:wordpress:*:* |
Information
Published : 2023-05-15 13:15
Updated : 2024-02-28 20:13
NVD link : CVE-2023-1207
Mitre link : CVE-2023-1207
CVE.ORG link : CVE-2023-1207
JSON object : View
Products Affected
riverside
- http_headers
CWE
No CWE.