CVE-2018-1000131
Summary
| CVE | CVE-2018-1000131 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-14 13:29:00 UTC |
| Updated | 2018-04-13 13:45:00 UTC |
| Description | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wpsupportplus | Wp Support Plus Responsive Ticket System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WP Support Plus Responsive Ticket System < 9.0.3 - Multiple Authenticated SQL Injection | MISC | wpvulndb.com | Third Party Advisory |
| exp/wpsupportplus.md at master · 00theway/exp · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| WP Support Plus Responsive Ticket System – WordPress plugin | WordPress.org | CONFIRM | wordpress.org | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.