CVE-2022-0846
SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi
Record summary
CVE-2022-0846 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 30, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SpeakOut! Email Petitions | CVE List | 2.14.15.1 to < 2.14.15.1 | affected |
speakout\!_email_petitionsBrowse speakout\!_email_petitions_project / speakout\!_email_petitions | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALSpeakOut Email Petitions < 2.14.15.1 - SQL InjectionCVSS 9.8
The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Fixed in version 2.14.15.1
Source: ProjectDiscovery