CVE-2022-3142: NEX-Forms < 7.9.7 - Authenticated SQLi
Published Sep 19, 2022
·Updated
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.
Affected Software
1 affected component
Basixonline Nex-forms Wordpress<7.9.7
Event History
Sep 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-3142.
2
What is the severity of CVE-2022-3142?
The severity of CVE-2022-3142 is high.
3
What is the affected software for CVE-2022-3142?
The affected software for CVE-2022-3142 is the NEX-Forms WordPress plugin before version 7.9.7.
4
How does CVE-2022-3142 impact the affected software?
CVE-2022-3142 allows SQL injections in the affected NEX-Forms WordPress plugin before version 7.9.7.
5
Is there a fix available for CVE-2022-3142?
Yes, updating the NEX-Forms WordPress plugin to version 7.9.7 or higher fixes CVE-2022-3142.