First published: Wed Jul 17 2019(Updated: )
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer | <7.3.19.727 |
https://plugins.trac.wordpress.org/changeset/2121566/fv-wordpress-flowplayer/trunk/models/db.php
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13573 is a SQL injection vulnerability in the FolioVision FV Flowplayer Video Player plugin for WordPress.
The severity of CVE-2019-13573 is critical with a CVSS score of 9.8.
CVE-2019-13573 allows a remote attacker to execute arbitrary SQL commands on the affected system.
Versions up to and excluding 7.3.19.727 of FolioVision FV Flowplayer Video Player plugin for WordPress are affected by CVE-2019-13573.
To mitigate the CVE-2019-13573 vulnerability, update the FolioVision FV Flowplayer Video Player plugin for WordPress to version 7.3.19.727 or later.