Web / CMS
SQL / NoSQL Injection
Elementor Website Builder <= 3.10.0 - Admin+ SQLi
Elementor Website Builder <= 3.10.0 – Admin+ SQLi The plugin does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL
.png)
Overview
Elementor Website Builder <= 3.10.0 – Admin+ SQLi
The plugin does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
Vulnerability details
Elementor Website Builder <= 3.10.0 – Admin+ SQLi The plugin does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
Disclosure timeline
2023-01-20 Reported On
2023-05-02 Made Public On
2023-05-01 Fixed On
References
Credits
Sanjay Das
















