CVE-2022-1692
CP Image Store with Slideshow < 1.0.68 - Unauthenticated SQLi
Record summary
CVE-2022-1692 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CP Image Store with Slideshow | CVE List | 1.0.68 to < 1.0.68 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALCP Image Store with Slideshow <= 1.0.67 - SQL InjectionCVSS 9.8
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack.
Impact
Unauthenticated attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise.
Remediation
Update to version 1.0.68 or later.
Source: ProjectDiscovery