CVE-2022-4158

CWE-89SQL Injection3 documents3 sources
Severity
7.5HIGH
EPSS
1.3%
top 20.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the site's database.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5unknown/contest_gallery< 19.1.5.1
CVEListV5unknown/contest_gallery_pro< 19.1.5.1

🔴Vulnerability Details

2
CVEList
Contest Gallery < 19.1.5 - Unauthenticated SQL Injection2022-12-26
GHSA
GHSA-x2v8-685r-x7hf: The Contest Gallery WordPress plugin before 192022-12-26
CVE-2022-4158 (HIGH CVSS 7.5) | The Contest Gallery WordPress plugi | cvebase.io