Extension WordPress
Vulnérabilités Podcast Importer SecondLine
Cette page rassemble les failles publiées pour Podcast Importer SecondLine, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Podcast Importer SecondLine
2 fiches
Podcast Importer SecondLine < 1.3.8 – SQL Injection
The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file.
[*, 1.3.8)
1.3.8
21/03/2022
Podcast Importer SecondLine <= 1.1.4 – Server-Side Request Forgery
Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 and below for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page.
[*, 1.1.5)
1.1.5
13/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.