CVE-2012-5327: SQL Injection
Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) deleteusrgrp[] parameter in a deleteusergroups action, (2) usergroup parameter in an addusertogroup action, or (3) addforumgroupid parameter in an addforumsubmit action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5327?
CVE-2012-5327 is classified as a critical vulnerability due to its potential for SQL injection leading to full compromise of the database.
How do I fix CVE-2012-5327?
To fix CVE-2012-5327, you should upgrade the Mingle Forum plugin to version 1.0.33 or later.
What types of SQL commands can be executed via CVE-2012-5327?
CVE-2012-5327 allows remote authenticated users to execute arbitrary SQL commands through specific parameters passed to the Mingle Forum plugin.
Who is affected by CVE-2012-5327?
CVE-2012-5327 affects users of the Mingle Forum plugin version 1.0.32.1 and earlier for WordPress.
Is user authentication required to exploit CVE-2012-5327?
Yes, remote authenticated users are required to exploit CVE-2012-5327 through the targeted SQL injection parameters.