Ketchup Restaurant Reservations <= 1.0.0 - Unauthenticated Blind SQLi
CVE-2022-2754
9.8CRITICAL
Summary
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
Affected Version(s)
Ketchup Restaurant Reservations 1.0.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bastijn Ouwendijk