CVE-2023-5761: SQL Injection
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5761?
CVE-2023-5761 is classified as a medium severity SQL injection vulnerability.
How do I fix CVE-2023-5761?
To fix CVE-2023-5761, update the Burst Statistics plugin to version 1.4.7 or later for the free version and 1.5.1 or later for the pro version.
Which versions of Burst Statistics are affected by CVE-2023-5761?
CVE-2023-5761 affects Burst Statistics plugin versions 1.4.0 to 1.4.6.1 for the free version and 1.4.0 to 1.5.0 for the pro version.
What does CVE-2023-5761 exploit?
CVE-2023-5761 exploits the SQL injection vulnerability via the 'url' parameter due to insufficient escaping.
Can CVE-2023-5761 allow unauthorized access?
Yes, CVE-2023-5761 can potentially allow unauthorized access to sensitive information in the database.