CVE-2019-13571
Advanced Contact Form 7 DB <= 1.6.2 - SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
Se presenta una vulnerabilidad de inyección SQL en el complemento Advanced CF7 DB de Vsourz Digital hasta versión 1.6.1 para WordPress. La explotación con éxito de esta vulnerabilidad permitiría a un atacante remoto ejecutar comandos SQL arbitrarios sobre el sistema afectado.
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. 1.7.0 contained an additional security patch.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-07-11 CVE Reserved
- 2019-07-29 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-08-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://fortiguard.com/zeroday/FG-VD-19-093 | Broken Link | |
https://plugins.trac.wordpress.org/changeset/2123623 | Release Notes | |
https://wordpress.org/plugins/advanced-cf7-db/#developers | Third Party Advisory | |
https://wpvulndb.com/vulnerabilities/9479 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/beerpwn/ctf/blob/master/CVE/CVE-2019-13571/report.pdf | 2024-08-04 | |
https://github.com/beerpwn/ctf/tree/master/CVE/CVE-2019-13571 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vsourz Search vendor "Vsourz" | Advanced Cf7 Db Search vendor "Vsourz" for product "Advanced Cf7 Db" | <= 1.6.1 Search vendor "Vsourz" for product "Advanced Cf7 Db" and version " <= 1.6.1" | wordpress |
Affected
|