CVE-2022-45805
WordPress Paytm Payment Gateway Plugin <= 2.7.3 is vulnerable to SQL Injection
Record summary
CVE-2022-45805 has a selected CVSS score of 8.2 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 5, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 2.7.3 | affected |
payment_gatewayBrowse paytm / payment_gatewayDefault status: unknown | CVE List | Through 2.7.3 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Paytm Payment Gateway <=2.7.3 - SQL InjectionCVSS 9.8
WordPress Paytm Payment Gateway plugin through 2.7.3 contains a SQL injection vulnerability. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.
Remediation
Update to version 2.7.7 or a newer patched version.
Source: ProjectDiscovery