|
|||
Rule General Information |
---|
Release Date: | 2021-12-20 | |
Rule Name: | WordPress Loginizer SQL Injection Vulnerability (CVE-2017-12650) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header. | |
Impact: | An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://blog.wpscans.com/sql-injection-and-csrf-security-vulnerability-in-loginizer/ https://sv.wordpress.org/plugins/loginizer/#developers https://wpvulndb.com/vulnerabilities/8883 |
|
Solutions |
---|
The vendor has released upgrade patches to fix vulnerabilities, please visit: https://sv.wordpress.org/plugins/loginizer/#developers |