9.8
CVE-2022-3241
- EPSS 4.45%
- Veröffentlicht 02.01.2023 22:15:15
- Zuletzt bearbeitet 10.04.2025 19:15:48
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Build App Online <= 1.0.18 - Unauthenticated SQL Injection
The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Mögliche Gegenmaßnahme
Build App Online: Update to version 1.0.19, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Build App Online
Version
*-1.0.18
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rahamsolutions ≫ Build App Online SwPlatformwordpress Version < 1.0.19
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.45% | 0.887 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|