CVE-2023-0279: Media Library Assistant < 3.06 - Admin+ SQLi
Published Feb 27, 2023
·Updated
The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Affected Software
1 affected component
Media Library Assistant Project Media Library Assistant Wordpress<3.06
Event History
Feb 27, 2023
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0279?
CVE-2023-0279 has a high severity rating due to the potential for SQL injection by high privilege users.
2
How do I fix CVE-2023-0279?
To fix CVE-2023-0279, update the Media Library Assistant plugin to version 3.06 or later.
3
Who is affected by CVE-2023-0279?
CVE-2023-0279 affects users of the Media Library Assistant WordPress plugin versions prior to 3.06.
4
What type of vulnerability is CVE-2023-0279?
CVE-2023-0279 is a SQL injection vulnerability.
5
Can CVE-2023-0279 be exploited remotely?
No, CVE-2023-0279 requires high privilege users such as administrators to exploit the vulnerability.