PT-2026-33309 · Designinvento+1 · Directorypress – Business Directory/Classified Ad Listing+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DirectoryPress – Business Directory And Classified Ad Listing versions prior to 3.6.27
Description
An issue exists where unauthenticated attackers can perform SQL Injection, a technique used to interfere with the queries that an application makes to its database. This occurs due to insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query. The flaw is triggered via the
packages parameter, allowing attackers to append additional SQL queries to extract sensitive information from the database.Recommendations
Update DirectoryPress – Business Directory And Classified Ad Listing to version 3.6.27 or later.
Avoid using the
packages parameter until the plugin is updated.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directorypress – Business Directory/Classified Ad Listing
Directorypress