Vulnerability Description
The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Multimedial Images Project | Multimedial Images | <= 1.0b |
References
- https://bulletin.iese.de/post/multimedial-images_1-0bExploitThird Party Advisory
- https://wpscan.com/vulnerability/cf336783-9959-413d-a5d7-73c7087426d8ExploitThird Party Advisory
- https://bulletin.iese.de/post/multimedial-images_1-0bExploitThird Party Advisory
- https://wpscan.com/vulnerability/cf336783-9959-413d-a5d7-73c7087426d8ExploitThird Party Advisory
FAQ
What is CVE-2022-4370?
CVE-2022-4370 is a vulnerability with a CVSS score of 7.2 (HIGH). The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role a...
How severe is CVE-2022-4370?
CVE-2022-4370 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4370?
Check the references section above for vendor advisories and patch information. Affected products include: Multimedial Images Project Multimedial Images.