Record summary

CVE-2022-0747 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 30, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Infographic Maker – iList

CVE List4.3.8 to < 4.3.8affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALInfographic Maker iList < 4.3.8 - SQL InjectionCVSS 9.8

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the WordPress site.

Remediation

Fixed in version 4.3.8

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022sqliwordpresswp-pluginwpinfographic-and-list-builder-ilistwpscanquantumcloudvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:quantumcloud:infographic_maker:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3