CVE-2015-10099: CP Appointment Calendar Plugin dex_appointments.php dex_process_ready_to_go_appointment sql injection
A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dexprocessreadytogoappointment of the file dexappointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack remotely. The patch is named e29a9cdbcb0f37d887dd302a05b9e8bf213da01d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-225351.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-10099?
The severity of CVE-2015-10099 is critical.
What is the affected software of CVE-2015-10099?
The affected software of CVE-2015-10099 is CP Appointment Calendar Plugin up to version 1.1.5 on WordPress.
What is the vulnerability in CVE-2015-10099?
The vulnerability in CVE-2015-10099 is a SQL injection vulnerability in the function dex_process_ready_to_go_appointment of the file dex_appointments.php of CP Appointment Calendar Plugin.
How can I fix CVE-2015-10099?
To fix CVE-2015-10099, it is recommended to update CP Appointment Calendar Plugin to a version higher than 1.1.5 or apply any available patches or security fixes provided by the vendor.
What is the CWE category of CVE-2015-10099?
The CWE category of CVE-2015-10099 is CWE-89 (SQL Injection).