Description
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-3011 Vulnerability (CVE-2019-3011)
WordPress Plugin Meks Flexible Shortcodes Cross-Site Scripting (1.3.4)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2023-6129)
WordPress Plugin WP-PostViews Cross-Site Request Forgery (1.62)
WordPress Plugin YITH Maintenance Mode Cross-Site Scripting (1.1.4)