9.8

CVE-2022-4099

Exploit

Joy Of Text Lite < 2.3.1 - Unauthenticated SQLi

Joy Of Text Lite – SMS messaging for WordPress <= 2.3.0 - Unauthenticated SQL Injection

The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection
Mögliche Gegenmaßnahme
Joy Of Text Lite – SMS messaging for WordPress.: Update to version 2.3.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetcloudsmsJoy Of Text Lite SwPlatformwordpress Version < 2.3.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Joy Of Text Lite – SMS messaging for WordPress.
Version *-2.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.594
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/a282dd39-926d-406b-b8f5-e4c6e0c2c028
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/fb11ad61-4ee7-45d2-a8e4-388f86bf4a0e
Third Party Advisory