CVE-2022-1182
Visual Slide Box Builder <= 3.2.9 - Subscriber+ SQLi
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL Injections
El plugin Visual Slide Box Builder de WordPress versiones hasta 3.2.9, no sanea y escapa de varios parĂ¡metros antes de usarlos en sentencias SQL por medio de algunas de sus acciones AJAX disponibles para cualquier usuario autenticado (como el suscriptor), lo que conlleva a inyecciones SQL
*Credits:
p7e4
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-03-30 CVE Reserved
- 2022-04-19 CVE Published
- 2023-12-07 EPSS Updated
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/01d108bb-d134-4651-9c74-babcc88da177 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Visual Slide Box Builder Project Search vendor "Visual Slide Box Builder Project" | Visual Slide Box Builder Search vendor "Visual Slide Box Builder Project" for product "Visual Slide Box Builder" | <= 3.2.9 Search vendor "Visual Slide Box Builder Project" for product "Visual Slide Box Builder" and version " <= 3.2.9" | wordpress |
Affected
|