HIGH
BadgeOS < 3.7.1.3 - Subscriber+ SQLi
Published Sep 19, 2022
8.8
HIGHCVSS 3.1
EPSS 1.32%
Description
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
Affected products
- Vendor n/a Product BadgeOS Defaultunknown
Affected
- ≥ 3.7.1.3, < 3.7.1.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | BadgeOS | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35179 Advisory
- https://wpscan.com/vulnerability/8743534f-8ebd-496a-99bc-5052a8bac86a x_refsource_MISCExploitPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35179 | Advisory | |
| https://wpscan.com/vulnerability/8743534f-8ebd-496a-99bc-5052a8bac86a | x_refsource_MISCExploitPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 19, 2022
Updated Aug 3, 2024
Reserved Aug 23, 2022
Link CVE-2022-2958
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data