VYPR
Unrated severityNVD Advisory· Published Jun 6, 2022· Updated Aug 3, 2024

Logo Slider <= 1.4.8 - Admin+ SQLi

CVE-2022-1687

Description

The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.