Record summary

CVE-2022-1692 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

CP Image Store with Slideshow

CVE List1.0.68 to < 1.0.68affected

Nuclei templates

1
ProjectDiscoveryCRITICALCP Image Store with Slideshow <= 1.0.67 - SQL InjectionCVSS 9.8

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack.

Impact

Unauthenticated attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise.

Remediation

Update to version 1.0.68 or later.

WeaknessesCWE-89
AuthorsShivam Kamboj
Template tagscvecve2022wordpresswpwp-pluginsqlicp-image-storeunauth
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

3