CVE-2022-1688
PoC ×2—CVSS 3.1
2.7 low
EPSS
<1%p54
Published
()
Modified
Description
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections
- Vendors
- datainterlock
- Products
- note press
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.