Segurium Research Advisories depicter
Depicter 4.8.0 and earlier: SQL injection
Depicter 4.8.1 rewrites the lead export query. Form field names from public submissions went straight into a raw MAX(IF()) SQL fragment, and sort parameters reached ORDER BY with no check. Update sites on 4.8.0 or earlier.
- Plugin
- Depicter
depicter - Affected versions
- 4.8.0 and earlier
- Fixed in
4.8.1- Class
- SQL injection
- Severity
- high Segurium Research assessment. No CVSS score published yet.
- CVE
- None assigned at the time of writing
- Installs
- 80,000 active
- Patch released
- Sources