CVE-2018-1002000 Vulnerability Details

  /     /     /  

CVE-2018-1002000 Metadata Quick Info

CVE Published: 03/12/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: larry_cashdollar | Vendor: Kiboko Labs https://calendarscripts.info/ | Product: Arigato Autoresponder and Newsletter
Status : PUBLISHED

CVE-2018-1002000 Description

There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Blind SQL injection in WordPress Plugin Arigato Autoresponder and Newsletter v2.5.1.8
Source: Kiboko Labs https://calendarscripts.info/

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).