Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-21661
HistoryJan 06, 2022 - 12:00 a.m.

CVE-2022-21661

2022-01-0600:00:00
ubuntu.com
ubuntu.com
78

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

0.934 High

EPSS

Percentile

99.1%

WordPress is a free and open-source content management system written in
PHP and paired with a MariaDB database. Due to improper sanitization in
WP_Query, there can be cases where SQL injection is possible through
plugins or themes that use it in a certain way. This has been patched in
WordPress version 5.8.3. Older affected versions are also fixed via
security release, that go back till 3.7.37. We strongly recommend that you
keep auto-updates enabled. There are no known workarounds for this
vulnerability.

Bugs

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

0.934 High

EPSS

Percentile

99.1%