Record summary

CVE-2022-0786 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

KiviCare – Clinic & Patient Management System (EHR)

CVE List2.3.9 to < 2.3.9affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress KiviCare <2.3.9 - SQL InjectionCVSS 9.8

WordPress KiviCare plugin before 2.3.9 contains a SQL injection vulnerability. The plugin does not sanitize and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to the WordPress database.

Remediation

Update to the latest version of the KiviCare plugin (2.3.9) or apply the provided patch to fix the SQL Injection vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022sqlikivicare-clinic-management-systemunauthwordpresswp-pluginwpwpscaniqonicvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2