CVE-2022-0773

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:documentor_project:documentor:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:39

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/55b89de0-30ed-4f98-935e-51f069faf6fc - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/55b89de0-30ed-4f98-935e-51f069faf6fc - Exploit, Third Party Advisory

09 May 2022, 15:01

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/55b89de0-30ed-4f98-935e-51f069faf6fc - (MISC) https://wpscan.com/vulnerability/55b89de0-30ed-4f98-935e-51f069faf6fc - Exploit, Third Party Advisory
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:documentor_project:documentor:*:*:*:*:*:wordpress:*:*

02 May 2022, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-02 16:15

Updated : 2024-11-21 06:39


NVD link : CVE-2022-0773

Mitre link : CVE-2022-0773

CVE.ORG link : CVE-2022-0773


JSON object : View

Products Affected

documentor_project

  • documentor
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')