CVE-2017-14723SQL Injection in Wordpress

CWE-89SQL Injection9 documents5 sources
Severity
9.8CRITICALNVD
EPSS
10.4%
top 6.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 23
Latest updateMay 17

Description

Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 4.8.3+dfsg-1 (bookworm)+1
Debianwordpress/wordpress< 4.8.2+dfsg-1+7
NVDwordpress/wordpress4.8.2+1

Patches

🔴Vulnerability Details

5
GHSA
GHSA-4f8m-x9c7-gvcq: Before version 42022-05-17
GHSA
GHSA-4cxp-jjp3-3qpw: WordPress before 42022-05-14
OSV
CVE-2017-16510: WordPress before 42017-11-02
OSV
CVE-2017-14723: Before version 42017-09-23
VulnCheck
WordPress wordpress Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2017

📋Vendor Advisories

2
Debian
CVE-2017-16510: wordpress - WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create...2017
Debian
CVE-2017-14723: wordpress - Before version 4.8.2, WordPress mishandled % characters and additional placehold...2017
CVE-2017-14723 — SQL Injection in Debian Wordpress | cvebase