CVE-2012-5328: SQL Injection
Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember action or (3) id parameter to fs-admin/fs-admin.php, or (4) editforumid parameter in an editsaveforum action to fs-admin/wpf-edit-forum-group.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5328?
CVE-2012-5328 is rated as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2012-5328?
To fix CVE-2012-5328, upgrade the Mingle Forum plugin to version 1.0.33 or later.
What versions of the Mingle Forum plugin are affected by CVE-2012-5328?
CVE-2012-5328 affects Mingle Forum versions 1.0.32.1 and earlier.
Can unauthenticated users exploit CVE-2012-5328?
No, CVE-2012-5328 requires authenticated users to exploit the SQL injection vulnerabilities.
What parameters are involved in the exploitation of CVE-2012-5328?
The vulnerability can be exploited via the memberid, groupid, and id parameters.