What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.2.
Explanation of Vulnerability in Simple Terms
Traveler Code versions 3.1.2 and earlier contain a SQL injection vulnerability in database query handling. An attacker can craft malicious input to execute arbitrary SQL commands, potentially reading, modifying, or deleting site data. The vulnerability requires specific conditions to exploit but can affect the entire application when successful.
What an attacker can do
Execute arbitrary SQL commands to read, modify, or delete database records.
Potential impact on your site
Attackers can steal sensitive data, modify site content, or disable the site entirely.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities