FlightLog <= 3.0.2 - Authenticated (Editor+) SQL Injection
highThe FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users
- CVSS:
- 7.2
- Affected:
- up to 3.0.2
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2021