CVE-2022-0739
BookingPress < 1.0.11 - Unauthenticated SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
9Exploited in Wild
-Decision
Descriptions
The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection
El plugin BookingPress de WordPress versiones anteriores a 1.0.11, no sanea correctamente los datos POST proporcionados por el usuario antes de que sean usados en una consulta SQL construida dinámicamente por medio de la acción AJAX bookingpress_front_get_category_services (disponible para usuarios no autenticados), conllevando a una inyección SQL no autenticada
The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-23 CVE Reserved
- 2022-02-28 CVE Published
- 2022-10-30 First Exploit
- 2024-08-02 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (10)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/destr4ct/CVE-2022-0739 | 2022-10-30 | |
https://github.com/BKreisel/CVE-2022-0739 | 2022-12-09 | |
https://github.com/Chris01s/CVE-2022-0739 | 2022-11-02 | |
https://github.com/viardant/CVE-2022-0739 | 2023-01-17 | |
https://github.com/G01d3nW01f/CVE-2022-0739 | 2022-12-23 | |
https://github.com/ElGanz0/CVE-2022-0739 | 2023-02-23 | |
https://github.com/lhamouche/Bash-exploit-for-CVE-2022-0739 | 2023-03-23 | |
https://github.com/hadrian3689/wp_bookingpress_1.0.11 | 2023-07-06 | |
https://wpscan.com/vulnerability/388cd42d-b61a-42a4-8604-99b812db2357 | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2684789 | 2022-03-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Reputeinfosystems Search vendor "Reputeinfosystems" | Bookingpress Search vendor "Reputeinfosystems" for product "Bookingpress" | < 1.0.11 Search vendor "Reputeinfosystems" for product "Bookingpress" and version " < 1.0.11" | wordpress |
Affected
|