What the vulnerability does
01Description
Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
Explanation of Vulnerability in Simple Terms
IP Blacklist Cloud versions up to 5.00 contain a SQL injection vulnerability in database queries. An attacker with high-level privileges can inject malicious SQL code to read, modify, or delete database contents. The vulnerability affects the entire application scope and requires administrative access to exploit.
What an attacker can do
Read, modify, or delete database records by injecting SQL commands into application queries.
Potential impact on your site
An admin account compromise could expose or corrupt all application data stored in the database.
Conditions required to exploit
Attacker must have high-level administrative privileges on the application.
Key dates
External resources
Related vulnerabilities