Vulnerability Description
SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Multi Feed Reader Project | Multi Feed Reader | <= 2.2.3 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN98617234/index.htmlThird Party AdvisoryVDB Entry
- https://wordpress.org/plugins/multi-feed-reader/#developersThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8844
- http://jvn.jp/en/jp/JVN98617234/index.htmlThird Party AdvisoryVDB Entry
- https://wordpress.org/plugins/multi-feed-reader/#developersThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8844
FAQ
What is CVE-2017-2195?
CVE-2017-2195 is a vulnerability with a CVSS score of 8.8 (HIGH). SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
How severe is CVE-2017-2195?
CVE-2017-2195 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2195?
Check the references section above for vendor advisories and patch information. Affected products include: Multi Feed Reader Project Multi Feed Reader.