Lucene search

K
nvd[email protected]NVD:CVE-2013-1408
HistoryMar 24, 2014 - 4:43 p.m.

CVE-2013-1408

2014-03-2416:43:02
CWE-89
web.nvd.nist.gov

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.3 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

43.3%

Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

Affected configurations

NVD
Node
wysija_newsletters_projectwysija_newslettersRange2.2wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.1wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.2wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.3wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.4wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.5wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.6wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.7wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.8wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.9wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.0.9.5wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.1wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.2wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.3wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.4wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.5wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.6wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.7wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.8wordpress
OR
wysija_newsletters_projectwysija_newslettersMatch2.1.9wordpress

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.3 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

43.3%