SQL Injection Vulnerability in Cardoza WordPress Poll Plugin by Vinoj Cardoza
CVE-2020-24315

7.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
26 August 2020

Summary

The Cardoza WordPress Poll Plugin, up to version 36, is susceptible to an SQL injection vulnerability. This issue arises from the inadequate escaping of user inputs in the pollid POST parameter. Malicious actors can exploit this flaw by submitting specially crafted SQL statements, granting them unauthorized access and allowing the potential dumping of the entire database. Proper input validation and escaping measures are crucial for safeguarding against such vulnerabilities.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.