CVE-2022-4154: Contest Gallery Pro < 19.1.5 - Admin+ SQL Injection
The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wpuserid GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Contest Gallery Pro WordPress plugin?
The vulnerability ID for the Contest Gallery Pro WordPress plugin is CVE-2022-4154.
What is the severity level of CVE-2022-4154?
The severity level of CVE-2022-4154 is medium with a severity value of 4.9.
Which version of the Contest Gallery Pro WordPress plugin is affected by CVE-2022-4154?
The Contest Gallery Pro WordPress plugin version up to 19.1.5.1 is affected by CVE-2022-4154.
How can CVE-2022-4154 be exploited?
CVE-2022-4154 can be exploited by malicious users with administrator privileges who can use the wp_user_id GET parameter to leak sensitive information.
Are there any references for CVE-2022-4154?
Yes, you can find references for CVE-2022-4154 at the following links: [link1](https://bulletin.iese.de/post/contest-gallery_19-1-4-1_5), [link2](https://wpscan.com/vulnerability/dac32ed4-d3df-420a-a2eb-9e7d2435826a).