Publish GHSA-87fg-9x5w-j3rm

This commit is contained in:
advisory-database[bot]
2023-12-28 22:13:09 +00:00
parent 4777263e91
commit f7e9859e78
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-87fg-9x5w-j3rm",
"modified": "2023-12-28T21:30:38Z",
"modified": "2023-12-28T22:11:55Z",
"published": "2023-12-20T15:30:19Z",
"aliases": [
"CVE-2023-38519"
],
"summary": "MainWP Dashboard SQL Command Injection vulnerability",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.\n\n",
"severity": [
{
@@ -14,13 +15,42 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "mainwp/mainwp"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.3.4"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 4.4.3.3"
}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38519"
},
{
"type": "WEB",
"url": "https://github.com/mainwp/mainwp/commit/8df951c0e8b2c2646cc57fc66b00767551cac400"
},
{
"type": "PACKAGE",
"url": "https://github.com/mainwp/mainwp"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/mainwp/wordpress-mainwp-plugin-4-4-3-3-sql-injection-vulnerability?_s_id=cve"
@@ -31,8 +61,8 @@
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2023-12-28T22:11:55Z",
"nvd_published_at": "2023-12-20T14:15:19Z"
}
}