PT-2022-14047 · WordPress · Note Press

Daniel Krohmer

+1

·

Published

2022-06-06

·

Updated

2022-06-15

·

CVE-2022-1689

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions The Note Press WordPress plugin versions 0.1.10 and earlier
Description The issue arises from the lack of sanitization and escaping of the Update parameter in SQL statements when updating notes via the admin dashboard, leading to an SQL injection. This allows for potential manipulation of database queries.
Recommendations For versions 0.1.10 and earlier, as a temporary workaround, consider restricting access to the admin dashboard to minimize the risk of exploitation. Avoid using the Update parameter in the affected SQL statements until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1689

Affected Products

Note Press