Vulnerability Details CVE-2017-1002004
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.055
EPSS Ranking 89.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-1002004
-
cpe:2.3:a:dtracker_project:dtracker:1.5