CVE-2022-0420
Summary
| CVE | CVE-2022-0420 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-07 09:15:00 UTC |
| Updated | 2022-03-11 16:38:00 UTC |
| Description | The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks |
NVD Known Affected Configurations (CPE 2.3)
Vendor Comments And Credit
Discovery Credit
LEGACY: qerogram
Legacy QID Mappings
- 730445 WordPress Plugin RegistrationMagic SQL Injection Vulnerability