Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
iws-geo-form-fields_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

CWE-89Dec 26, 20221 related artifact
CVSS9.8v3.1EPSS4.96%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX