WordPress WP Symposium plug-in "tray" SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
WordPress WP Symposium 14.12
Description:
WordPress WP Symposium plug-in is a network plug-in that adds social functions.
In WP Symposium 14.12 and other versions, when "action" is set to "getMailMessage" and "mid" is set to a valid message ID, the "tray" POST parameter value of wp-symposium/ajax/mail_functions.php is not properly filtered, which allows attackers to inject arbitrary SQL code.
<* Source: Kacper Szurek
Link: http://secunia.com/advisories/62643/
*>
Suggestion:
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://security.szurek.pl/wp-symposium-1410-multiple-xss-and-sql-injection.html
This article permanently updates the link address: