// For flags

CVE-2022-1182

Visual Slide Box Builder <= 3.2.9 - Subscriber+ SQLi

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL Injections

El plugin Visual Slide Box Builder de WordPress versiones hasta 3.2.9, no sanea y escapa de varios parĂ¡metros antes de usarlos en sentencias SQL por medio de algunas de sus acciones AJAX disponibles para cualquier usuario autenticado (como el suscriptor), lo que conlleva a inyecciones SQL

*Credits: p7e4
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-03-30 CVE Reserved
  • 2022-04-19 CVE Published
  • 2023-12-07 EPSS Updated
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Visual Slide Box Builder Project
Search vendor "Visual Slide Box Builder Project"
Visual Slide Box Builder
Search vendor "Visual Slide Box Builder Project" for product "Visual Slide Box Builder"
<= 3.2.9
Search vendor "Visual Slide Box Builder Project" for product "Visual Slide Box Builder" and version " <= 3.2.9"
wordpress
Affected