The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

#DARKWEB

Browse the largest dark web index on the internet. Search Onion sites via fulltext queries and browse them via Tor compatible browser (Brave or Tor Browser, ...).

A question and answer site for researchers, developers, and users of Tor.

Test On Your Security Posture. SOCRadar LABS is a new and developing platform which informs users about existing and possible cyber threats with the help of several cyber threat intelligence services.