Description
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin The Events Calendar Open Redirect (4.1.1)
Drupal Core 5.x Multiple Vulnerabilities (5.0 - 5.12)
Undertow CVE-2022-2764 Vulnerability (CVE-2022-2764)
WordPress Plugin Ecwid Ecommerce Shopping Cart Cross-Site Request Forgery (6.10.23)
WordPress Plugin MapifyLite (by MapifyPro) Cross-Site Scripting (3.3)