What the vulnerability does
01Description
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Explanation of Vulnerability in Simple Terms
Like Button Rating versions up to 2.6.61 contain a SQL injection vulnerability in database query handling. An authenticated attacker can inject malicious SQL commands to read sensitive data from the database, including user information and site configuration. The vulnerability also allows limited disruption of database availability. A patch version has not been publicly identified.
What an attacker can do
Read sensitive data from the site's database, including user records and configuration.
Potential impact on your site
Unauthorized access to user data, passwords, and site configuration stored in the database.
Conditions required to exploit
Attacker must have a user account with at least low-level privileges on the site.
Key dates
External resources
Related vulnerabilities