Vulnerability Description
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tribulant | Slideshow Gallery | 1.6.8 |
Related Weaknesses (CWE)
References
- https://ansawaf.blogspot.com/2019/04/xss-and-sqli-in-slideshow-gallery.htmlExploitThird Party Advisory
- https://docs.google.com/document/d/1rwN4hJkD5TJfCa16rsGwzYhzL-ODd2VLkFnPvAIq4Ys/Permissions RequiredThird Party Advisory
- https://ansawaf.blogspot.com/2019/04/xss-and-sqli-in-slideshow-gallery.htmlExploitThird Party Advisory
- https://docs.google.com/document/d/1rwN4hJkD5TJfCa16rsGwzYhzL-ODd2VLkFnPvAIq4Ys/Permissions RequiredThird Party Advisory
FAQ
What is CVE-2018-18018?
CVE-2018-18018 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
How severe is CVE-2018-18018?
CVE-2018-18018 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-18018?
Check the references section above for vendor advisories and patch information. Affected products include: Tribulant Slideshow Gallery.