davidfcarr Vulnerabilities and Affected Products
Vulnerabilities associated with RSVPMaker.
Products
Clear product- RSVPMarker5 vulnerabilities
- Quick Playground3 vulnerabilities
- RSVPMaker3 vulnerabilities
- My Marginalia1 vulnerability
- RSVPMaker for Toastmasters1 vulnerability
- RSVPMaker Volunteer Roles1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-1768CRITICAL | RSVPMaker <= 9.3.2 - Unauthenticated SQL InjectionThe RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505. | CVSS9.8v3.1 | EPSS12.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-1505CRITICAL | RSVPMaker <= 9.2.6 - Unauthenticated SQL InjectionThe RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6. CWE-89May 10, 2022 | CVSS9.8v3.1 | EPSS1.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1453CRITICAL | RSVPMaker <= 9.2.5 - Unauthenticated SQL InjectionThe RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5. | CVSS9.8v3.1 | EPSS7.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |