What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.5.
Explanation of Vulnerability in Simple Terms
Link Whisper Free versions up to 0.6.5 contain a SQL injection vulnerability in database queries. An attacker with low-level site access can craft malicious input to extract sensitive data from the database or disrupt site availability. The vulnerability requires authentication but affects the entire site scope.
What an attacker can do
Extract sensitive data from the site database or cause the database to become unavailable.
Potential impact on your site
Unauthorized access to database contents including user data, posts, and configuration; potential site downtime.
Conditions required to exploit
Attacker must have a low-privilege account on the site (subscriber or contributor level).
Key dates
External resources
Related vulnerabilities