Vulnerability Description
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Techytalk | Quick Chat | <= 4.14 |
Related Weaknesses (CWE)
References
- https://metalamin.github.io/Quick-Chat-SQLi-EN/Not ApplicableThird Party Advisory
- https://metalamin.github.io/Quick-Chat-SQLi-EN/Not ApplicableThird Party Advisory
FAQ
What is CVE-2019-1010104?
CVE-2019-1010104 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The a...
How severe is CVE-2019-1010104?
CVE-2019-1010104 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-1010104?
Check the references section above for vendor advisories and patch information. Affected products include: Techytalk Quick Chat.