What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Supsystic Slider by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Supsystic Slider by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.10.
Explanation of Vulnerability in Simple Terms
Slider by Supsystic versions up to 1.8.10 contain a SQL injection vulnerability accessible to high-privilege users. An attacker with admin or editor access can craft malicious input to extract or modify database contents. The vulnerability requires administrative credentials and does not affect data integrity, but can expose sensitive information and degrade site performance.
What an attacker can do
Read sensitive data from the site database, such as user credentials or configuration details.
Potential impact on your site
A compromised admin account could expose your database contents or cause service disruption.
Conditions required to exploit
Attacker must have high-level site access (admin or editor role); no user interaction required.
Key dates
External resources
Related vulnerabilities