Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log user-activity-log allows SQL Injection.This issue affects User Activity Log: from n/a through 1.6.2.
References
Configurations
History
08 Nov 2023, 18:49
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://patchstack.com/database/vulnerability/user-activity-log/wordpress-user-activity-log-plugin-1-6-2-sql-injection-vulnerability?_s_id=cve - Third Party Advisory | |
| CPE | cpe:2.3:a:solwininfotech:user_activity_log:*:*:*:*:*:wordpress:*:* | |
| First Time |
Solwininfotech user Activity Log
Solwininfotech |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
31 Oct 2023, 15:35
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-10-31 15:15
Updated : 2023-11-08 18:49
NVD link : CVE-2023-37966
Mitre link : CVE-2023-37966
JSON object : View
Products Affected
solwininfotech
- user_activity_log
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
