What the vulnerability does
01Description
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
Explanation of Vulnerability in Simple Terms
Dokan Pro versions up to 5.0.2 contain a SQL injection vulnerability in a database query that requires low-level authentication to exploit. An attacker with a user account can craft malicious input to read or modify database contents. The vulnerability affects multiple site functions due to scope change, and also causes partial service disruption.
What an attacker can do
Read or modify database records by injecting SQL commands into a query parameter.
Potential impact on your site
Unauthorized access to sensitive data and potential data modification; some site functions may become unavailable.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities