CVE-2015-7319: SQL Injection
Published Sep 29, 2015
·Updated
SQL injection vulnerability in cpabcappointmentsadminintcalendarlist.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
Affected Software
1 affected component
CodePeople Appointment Booking Calendar Wordpress<=1.1.7
Remediation
Event History
Sep 29, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7319?
CVE-2015-7319 has been classified as a high severity SQL injection vulnerability.
2
How does CVE-2015-7319 affect WordPress users?
CVE-2015-7319 allows remote attackers to execute arbitrary SQL commands on vulnerable WordPress sites.
3
How do I fix CVE-2015-7319?
To fix CVE-2015-7319, update the Appointment Booking Calendar plugin to version 1.1.8 or later.
4
What versions are affected by CVE-2015-7319?
CVE-2015-7319 affects versions of the Appointment Booking Calendar plugin prior to 1.1.8.
5
What type of vulnerability is CVE-2015-7319?
CVE-2015-7319 is an SQL injection vulnerability.