CVE-2022-1014
Summary
| CVE | CVE-2022-1014 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-23 08:16:00 UTC |
| Updated | 2022-10-29 02:57:00 UTC |
| Description | The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Labarta | Wp Contacts Manager | All | All | All | All |
| Application | Wp Contacts Manager Project | Wp Contacts Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WP Contacts Manager <= 2.2.4 - Unauthenticated SQLi WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: cydave
There are currently no legacy QID mappings associated with this CVE.