CVE-2017-1002028
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: larry0@me.com — http://www.vapidlabs.com/advisory.php?v=199
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| angrybyte | gallery-transformation | 1.0 | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.