CVE-2022-0411: Asgaros Forum < 2.0.0 - Subscriber+ Blind SQL Injection
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the postid parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Asgaros Forum WordPress plugin vulnerability?
The vulnerability ID for this Asgaros Forum WordPress plugin vulnerability is CVE-2022-0411.
What is the severity of the CVE-2022-0411 vulnerability?
The severity of the CVE-2022-0411 vulnerability is high with a severity value of 8.8.
How does the CVE-2022-0411 vulnerability affect the Asgaros Forum WordPress plugin?
The CVE-2022-0411 vulnerability affects the Asgaros Forum WordPress plugin by allowing SQL injection through the post_id parameter.
Which version of the Asgaros Forum WordPress plugin is affected by CVE-2022-0411 vulnerability?
The Asgaros Forum WordPress plugin version before 2.0.0 is affected by the CVE-2022-0411 vulnerability.
Are there any references available for more information about the CVE-2022-0411 vulnerability?
Yes, you can find more information about the CVE-2022-0411 vulnerability at the following references: 1. [WordPress Plugins Trac](https://plugins.trac.wordpress.org/changeset/2669226/asgaros-forum). 2. [WPScan](https://wpscan.com/vulnerability/35272197-c973-48ad-8405-538bfbafa172)