This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.
References
Configurations
History
24 Jan 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wpscan.com/vulnerability/6f3f460b-542a-4d32-8feb-afa1aef57e37 - Exploit |
07 Nov 2023, 04:02
| Type | Values Removed | Values Added |
|---|---|---|
| CWE |
08 Aug 2023, 11:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:riverside:http_headers:*:*:*:*:*:wordpress:*:* | |
| First Time |
Riverside http Headers
Riverside |
23 May 2023, 17:40
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Http Headers Project http Headers
Http Headers Project |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| CPE | cpe:2.3:a:http_headers_project:http_headers:*:*:*:*:*:wordpress:*:* | |
| References | (MISC) https://wpscan.com/vulnerability/6f3f460b-542a-4d32-8feb-afa1aef57e37 - Exploit |
15 May 2023, 13:26
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-05-15 13:15
Updated : 2025-01-24 21:15
NVD link : CVE-2023-1207
Mitre link : CVE-2023-1207
JSON object : View
Products Affected
riverside
- http_headers
CWE
No CWE.
