The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
                
            References
                    | Link | Resource | 
|---|---|
| https://plugins.trac.wordpress.org/changeset/2696254 | Patch Third Party Advisory | 
| https://wpscan.com/vulnerability/163069cd-98a8-4cfb-8b58-a6727a7d5c48 | Exploit Patch Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Information
                Published : 2022-04-11 08:15
Updated : 2022-04-14 20:40
NVD link : CVE-2022-1023
Mitre link : CVE-2022-1023
JSON object : View
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
                secondlinethemes
- podcast_importer_secondline


