Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CWE 1 Total

  • CWE-89 SQL Injection

Product Status

Learn more

Versions 1 Total

Default Status: unaffected

affected

Credits

  • Daniel Krohmer (Fraunhofer IESE) finder
  • Kunal Sharma (University of Kaiserslautern) finder
  • WPScan coordinator

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.

Authorized Data Publishers