Vulnerability Description
A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection. The attack may be initiated remotely. The patch is named 41230a81db0f671c570c2644bc2f80565ca83c5a. It is recommended to apply a patch to fix this issue.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/webuidesigning/NebulaX/commit/41230a81db0f671c570c2644bc2f805
- https://vuldb.com/?ctiid.289163
- https://vuldb.com/?id.289163
FAQ
What is CVE-2018-25106?
CVE-2018-25106 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy...
How severe is CVE-2018-25106?
CVE-2018-25106 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25106?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.