CVE-2020-5768: SQL Injection
Published Jul 17, 2020
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
Affected Software
1 affected component
Icegram Email Subscribers \& Newsletters Wordpress=4.4.8
Event History
Jul 17, 2020
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5768.
2
What is the severity of CVE-2020-5768?
The severity of CVE-2020-5768 is medium.
3
Which software version is affected by CVE-2020-5768?
Version 4.4.8 of the Icegram Email Subscribers & Newsletters Plugin for WordPress is affected by CVE-2020-5768.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-89.
5
How can I fix CVE-2020-5768?
To fix CVE-2020-5768, it is recommended to update the Icegram Email Subscribers & Newsletters Plugin for WordPress to a version that is not affected by the vulnerability.