CVE-2017-13137

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICAL
EPSS
0.5%
top 35.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 23
Latest updateMay 13

Description

The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-7hgh-c3w3-p3mw: The FormCraft Basic plugin 12022-05-13
CVEList
CVE-2017-13137: The FormCraft Basic plugin 12017-08-23
CVE-2017-13137 (CRITICAL CVSS 9.8) | The FormCraft Basic plugin 1.0.5 fo | cvebase.io