MOLIE – Instructure Canvas Linking tool [molie-instructure-canvas-linking-tool] <= 0.5 (unfixed + closed)
unknown
[en] The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 0.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 14, 2022
CVE-2021-25006 on NVD →
MOLIE – Instructure Canvas Linking tool [molie-instructure-canvas-linking-tool] <= 0.5 (unfixed + closed)
unknown
[en] The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection
- Affected:
- up to 0.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 14, 2022
CVE-2021-25007 on NVD →
MOLIE <= 0.5 - SQL Injection
high
The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection
- CVSS:
- 8.8
- Affected:
- up to 0.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 29, 2021
CVE-2021-25007 on NVD →
MOLIE – Instructure Canvas Linking tool <= 0.5 - Reflected Cross-Site Scripting
medium
The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 0.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 29, 2021
CVE-2021-25006 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database