Simple Quotation <= 1.3.2 - Subscriber+ SQL injection
CVE-2022-22735

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
14 March 2022

Summary

The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenticated users, such as subscriber to perform SQL injection attacks

Affected Version(s)

Simple Quotation 1.3.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

abhishek bhoir
.