CRITICAL
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress
Published Jul 29, 2019
9.8
CRITICALCVSS 3.1
EPSS 4.00%
Description
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
Affected products
No data.
- ≤ 1.6.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://fortiguard.com/zeroday/FG-VD-19-093 x_refsource_MISCBroken Link
- https://github.com/beerpwn/ctf/blob/master/CVE/CVE-2019-13571/report.pdf x_refsource_MISCExploitTechnical Description
- https://github.com/beerpwn/ctf/tree/master/CVE/CVE-2019-13571 x_refsource_MISCExploitTechnical Description
- https://plugins.trac.wordpress.org/changeset/2123623 x_refsource_MISCRelease NotesThird Party Advisory
- https://wordpress.org/plugins/advanced-cf7-db/#developers x_refsource_MISCThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9479 x_refsource_MISCThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://fortiguard.com/zeroday/FG-VD-19-093 | x_refsource_MISCBroken Link | |
| https://github.com/beerpwn/ctf/blob/master/CVE/CVE-2019-13571/report.pdf | x_refsource_MISCExploitTechnical Description | |
| https://github.com/beerpwn/ctf/tree/master/CVE/CVE-2019-13571 | x_refsource_MISCExploitTechnical Description | |
| https://plugins.trac.wordpress.org/changeset/2123623 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://wordpress.org/plugins/advanced-cf7-db/#developers | x_refsource_MISCThird Party Advisory | |
| https://wpvulndb.com/vulnerabilities/9479 | x_refsource_MISCThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 29, 2019
Updated Aug 4, 2024
Reserved Jul 11, 2019
Link CVE-2019-13571
CISA Vulnrichment
Updated n/a