CVE-2023-1730
SupportCandy < 3.1.5 - Unauthenticated SQLi
Record summary
CVE-2023-1730 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SupportCandyDefault status: unaffected | CVE List | Before 3.1.5 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALSupportCandy < 3.1.5 - Unauthenticated SQL InjectionCVSS 9.8
The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Fixed in version 3.1.5
Source: ProjectDiscovery