CVE-2017-1002027: SQL Injection
Published Sep 14, 2017
·Updated
Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rkuserlist.php.
Affected Software
1 affected component
Rayanehdownload Rk-responsive-contact-form Wordpress=1.0
Remediation
Patch Available
Event History
Sep 14, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1002027?
CVE-2017-1002027 is classified as a high severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2017-1002027?
To fix CVE-2017-1002027, ensure that the variable $delid is properly sanitized before it is used in SQL queries.
3
What plugin is affected by CVE-2017-1002027?
CVE-2017-1002027 affects the rk-responsive-contact-form plugin version 1.0.
4
Can CVE-2017-1002027 lead to data exposure?
Yes, CVE-2017-1002027 can lead to unauthorized access to the database, potentially exposing sensitive data.
5
Is there an update available for CVE-2017-1002027?
No official updates are available for CVE-2017-1002027, so it's recommended to limit the use of the vulnerable plugin.