PT-2022-23351 · WordPress · Contest Gallery
Minhtuanact
+1
·
Published
2022-08-23
·
Updated
2022-08-25
·
CVE-2022-36394
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contest Gallery plugin versions <= 17.0.4
Description
The issue is an authenticated SQL Injection vulnerability, affecting the Contest Gallery plugin at WordPress. This allows for SQL injection attacks when an attacker has author or higher privileges.
Recommendations
For versions <= 17.0.4, update to a version higher than 17.0.4 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's database interactions until a patch is available.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contest Gallery