The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
References
Link Resource
https://wpscan.com/vulnerability/8743534f-8ebd-496a-99bc-5052a8bac86a Exploit Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-09-19T14:01:05

Updated: 2022-09-19T14:01:05

Reserved: 2022-08-23T00:00:00


Link: CVE-2022-2958

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-19T14:15:11.050

Modified: 2022-09-21T06:29:02.163


Link: CVE-2022-2958

JSON object: View

cve-icon Redhat Information

No data.

CWE