Vulnerability Description
mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://addons.moosocial.com/stores
- https://moosocial.com/product/store-plugins/
- https://www.exploit-db.com/exploits/45330
- https://www.vulncheck.com/advisories/moosocial-store-plugin-sql-injection-via-pr
FAQ
What is CVE-2018-25371?
CVE-2018-25371 is a vulnerability with a CVSS score of 8.2 (HIGH). mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality....
How severe is CVE-2018-25371?
CVE-2018-25371 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25371?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.