Vulnerability Description
The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Custom Searchable Data Entry System Project | Custom Searchable Data Entry System | <= 1.7.1 |
Related Weaknesses (CWE)
References
- http://avveng.com/cve.htmlExploitThird Party Advisory
- https://plugins.trac.wordpress.org/log/custom-searchable-data-entry-system/Third Party Advisory
- http://avveng.com/cve.htmlExploitThird Party Advisory
- https://plugins.trac.wordpress.org/log/custom-searchable-data-entry-system/Third Party Advisory
FAQ
What is CVE-2020-10817?
CVE-2020-10817 is a vulnerability with a CVSS score of 8.8 (HIGH). The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.
How severe is CVE-2020-10817?
CVE-2020-10817 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10817?
Check the references section above for vendor advisories and patch information. Affected products include: Custom Searchable Data Entry System Project Custom Searchable Data Entry System.