What the vulnerability does
01Description
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
Explanation of Vulnerability in Simple Terms
Depicter Slider versions up to 4.8.0 contain a SQL injection vulnerability that allows attackers to read sensitive data from the site's database without authentication. The attack requires specific conditions to be met and does not allow data modification. Site administrators should update to a version newer than 4.8.0 to eliminate this risk.
What an attacker can do
Read sensitive data from the site's database, including user information and configuration details.
Potential impact on your site
Unauthorized access to database contents, potentially exposing user data, credentials, and site configuration.
Conditions required to exploit
Network access to the site; no authentication required, but attack complexity is high.
Key dates
External resources
Related vulnerabilities