CVE-2022-3720 Information
Nov 25, 2022
cve
Description
The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements which could lead to SQL Injection exploitable by high privilege users
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/0139a23c-4896-4aef-ab56-dcf7f07f01e5
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: