Showing 1 vulnerability on this page for daily_prayer_time

Signals CISA KEV Ransomware Nuclei
daily_prayer_time_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Daily Prayer Time < 2022.03.01 - Unauthenticated SQLi

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CWE-89Apr 18, 20221 related artifact
CVSS9.8v3.1EPSS9.28%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX