CVE-2022-1688SQL Injection in Note Press

CWE-89SQL Injection3 documents3 sources
Severity
2.7LOWNVD
EPSS
0.2%
top 60.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateJun 9

Description

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jp7j-jjcw-94q5: The Note Press WordPress plugin through 02022-06-09
CVEList
Note Press <= 0.1.10 - Admin+ SQLi via id2022-06-06
CVE-2022-1688 — SQL Injection in Note Press | cvebase