The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Internet-formation Internet-formation wp-advanced-search | |
| CPEs | cpe:2.3:a:internet-formation:wp-advanced-search:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Wp-advanced-search Project Wp-advanced-search Project wp-advanced-search | Internet-formation Internet-formation wp-advanced-search | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:48:58.138Z
Reserved: 2020-04-23T00:00:00
Link: CVE-2020-12104
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2020-05-05T15:15:12.420
Modified: 2024-11-21T04:59:15.183
Link: CVE-2020-12104
 Redhat
                        Redhat
                    No data.