Lucene search

K
cvelistWPScanCVELIST:CVE-2022-1688
HistoryJun 06, 2022 - 8:51 a.m.

CVE-2022-1688 Note Press <= 0.1.10 - Admin+ SQLi via id

2022-06-0608:51:23
CWE-89
WPScan
www.cve.org

4.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.8%

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

CNA Affected

[
  {
    "product": "Note Press",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThanOrEqual": "0.1.10",
        "status": "affected",
        "version": "0.1.10",
        "versionType": "custom"
      }
    ]
  }
]

4.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.8%

Related for CVELIST:CVE-2022-1688