CVE-2018-25371: mooSocial Store Plugin 2.6 SQL Injection via product parameter
mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25371?
The severity of CVE-2018-25371 is high with a score of 8.2.
How do I fix CVE-2018-25371?
To fix CVE-2018-25371, update the mooSocial Store Plugin to the latest version that addresses this SQL injection vulnerability.
What types of attacks can exploit CVE-2018-25371?
CVE-2018-25371 can be exploited using boolean-based blind, time-based blind, or stacked query techniques.
Who is affected by CVE-2018-25371?
Unauthenticated attackers can exploit CVE-2018-25371 to manipulate database queries in affected installations of the mooSocial Store Plugin.
What functionality is affected by CVE-2018-25371?
CVE-2018-25371 affects the product parameter in the URL rewrite functionality of the mooSocial Store Plugin.