CVE-2022-4152

CWE-89SQL Injection3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.9%
top 24.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5unknown/contest_gallery< 19.1.5
CVEListV5unknown/contest_gallery_pro< 19.1.5

🔴Vulnerability Details

2
GHSA
GHSA-6vhw-xj9w-j95w: The Contest Gallery WordPress plugin before 192022-12-26
CVEList
Contest Gallery < 19.1.5 - Author+ SQL Injection2022-12-26
CVE-2022-4152 (MEDIUM CVSS 6.5) | The Contest Gallery WordPress plugi | cvebase.io