Auto Generated CVE annotations [Wed Oct 5 08:55:29 UTC 2022] 🤖

patch-1
GitHub Action 2022-10-05 08:55:29 +00:00
parent 5ee311279a
commit b244065a5d
1 changed files with 6 additions and 2 deletions

View File

@ -3,17 +3,21 @@ id: CVE-2022-1768
info: info:
name: RSVPMaker WordPress plugin <= 9.3.2 - SQL Injection name: RSVPMaker WordPress plugin <= 9.3.2 - SQL Injection
author: edoardottt author: edoardottt
severity: critical severity: high
description: | description: |
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2.
reference: reference:
- https://gist.github.com/Xib3rR4dAr/441d6bb4a5b8ad4b25074a49210a02cc - https://gist.github.com/Xib3rR4dAr/441d6bb4a5b8ad4b25074a49210a02cc
- https://wordpress.org/plugins/rsvpmaker/ - https://wordpress.org/plugins/rsvpmaker/
- https://nvd.nist.gov/vuln/detail/CVE-2022-1768 - https://nvd.nist.gov/vuln/detail/CVE-2022-1768
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2725322%40rsvpmaker&new=2725322%40rsvpmaker&sfp_email=&sfph_mail=
classification: classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2022-1768 cve-id: CVE-2022-1768
cwe-id: CWE-89
metadata: metadata:
verified: true verified: "true"
tags: cve,cve2022,wordpress,wp-plugin,wp,sqli,rsvpmaker tags: cve,cve2022,wordpress,wp-plugin,wp,sqli,rsvpmaker
requests: requests: