CVE-2022-0867 Vulnerability Details
/
/
/
CVE-2022-0867 Metadata Quick Info
CVE Published: 16/05/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022
Source: WPScan |
Vendor: Unknown |
Product: Pricing Table Plugin
Status : PUBLISHED
CVE-2022-0867 Description
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-89
CWE Name: CWE-89 SQL Injection
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).