9.4 CRITICAL
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): LOW
WordPress tPlayer plugin <= 1.2.1.6 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-with-playlist allows SQL Injection.This issue affects tPlayer: from n/a through <= 1.2.1.6.
References
Affected products
- =<<= 1.2.1.6
Matching in nixpkgs
pkgs.rustplayer
Local audio player and network m3u8 radio player using a terminal interface
-
nixos-unstable 1.1.2-unstable-2024-07-14
- nixpkgs-unstable 1.1.2-unstable-2024-07-14
- nixos-unstable-small 1.1.2-unstable-2024-07-14
Package maintainers
-
@oluceps oluceps <nixos@oluceps.uk>