CVE-2022-3981

The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
Configurations

Configuration 1 (hide)

cpe:2.3:a:icegram:email_subscribers_\&_newsletters:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:20

Type Values Removed Values Added
Summary
  • (es) El complemento de WordPress Icegram Express anterior a 5.5.1 no sanitiza ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que genera una inyección de SQL explotable por cualquier usuario autenticado, como el suscriptor.
References () https://wpscan.com/vulnerability/78054d08-0227-426c-903d-d146e0919028 - Third Party Advisory () https://wpscan.com/vulnerability/78054d08-0227-426c-903d-d146e0919028 - Third Party Advisory

Information

Published : 2022-12-12 18:15

Updated : 2025-04-22 15:16


NVD link : CVE-2022-3981

Mitre link : CVE-2022-3981

CVE.ORG link : CVE-2022-3981


JSON object : View

Products Affected

icegram

  • email_subscribers_\&_newsletters
CWE

No CWE.