7.2

CVE-2022-4372

Exploit

Web Invoice <= 2.1.3 - Authenticated SQLi

Web Invoice <= 2.1.3 - Authenticated SQL Injection

The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well
Mögliche Gegenmaßnahme
Web Invoice – Invoicing and billing for WordPress: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Web Invoice ProjectWeb Invoice SwPlatformwordpress Version <= 2.1.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Web Invoice – Invoicing and billing for WordPress
Version *-2.1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.577
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://bulletin.iese.de/post/web-invoice_2-1-3_2
Third Party Advisory
Exploit
https://wpscan.com/vulnerability/218f8015-e14b-46a8-889d-08b2b822f8ae
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/272515e3-18ae-4e7f-8503-722d7964b3c2
Third Party Advisory