What the vulnerability does
01Description
Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.
Explanation of Vulnerability in Simple Terms
Create by Mediavine versions up to 2.5.3 contain a SQL injection vulnerability accessible to authenticated users. An attacker with low-level account access can craft malicious input to execute arbitrary SQL queries against the site database. This can expose sensitive data across the entire site and degrade database performance. Update to a version newer than 2.5.3.
What an attacker can do
Read or modify database contents, including user data and site configuration.
Potential impact on your site
Unauthorized access to sensitive database records; potential data breach affecting all users.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities