CVE-2022-0747
Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection
Record summary
CVE-2022-0747 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 30, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Infographic Maker – iList | CVE List | 4.3.8 to < 4.3.8 | affected |
infographic_makerBrowse quantumcloud / infographic_maker | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALInfographic Maker iList < 4.3.8 - SQL InjectionCVSS 9.8
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the WordPress site.
Remediation
Fixed in version 4.3.8
Source: ProjectDiscovery