Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-1768

Опубликовано: 13 июн. 2022
Источник: nvd
CVSS3: 9.8
CVSS3: 7.5
CVSS2: 5
EPSS Высокий

Описание

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2.

Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:carrcommunications:rsvpmaker:*:*:*:*:*:wordpress:*:*
Версия до 9.3.2 (включая)

EPSS

Процентиль: 99%
0.86112
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

EPSS

Процентиль: 99%
0.86112
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты