CVE-2017-12199: SQL Injection
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogueupdateorder list-item, videoupdateorder video-item, imageupdateorder list-item, taggroupupdateorder listitem, categoryproductsupdateorder category-product-item, customfieldsupdateorder field-item, categoriesupdateorder category-item, subcategoriesupdateorder subcategory-item, and tagsupdateorder tag-list-item.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12199?
CVE-2017-12199 is classified as a medium severity SQL injection vulnerability.
How do I fix CVE-2017-12199?
To fix CVE-2017-12199, update the Etoile Ultimate Product Catalog plugin to the latest version or implement input validation to mitigate SQL injection risks.
What is the impact of CVE-2017-12199?
The impact of CVE-2017-12199 allows attackers to exploit SQL injection vulnerabilities, potentially leading to unauthorized data access.
Which software versions are affected by CVE-2017-12199?
CVE-2017-12199 affects version 4.2.11 of the Etoile Ultimate Product Catalog plugin for WordPress.
How can I identify exploitation of CVE-2017-12199?
Exploitation of CVE-2017-12199 can often be identified through unusual database queries or errors related to database access in logs.