CVE-2022-4162: Contest Gallery < 19.1.5 - Author+ SQL Injection
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cgrow POST parameter before concatenating it to an SQL query in 3row-order.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4162?
CVE-2022-4162 is a vulnerability in the Contest Gallery WordPress plugin and Contest Gallery Pro WordPress plugin that allows malicious users with at least author privilege to leak sensitive information.
What software versions are affected by CVE-2022-4162?
The Contest Gallery WordPress plugin before version 19.1.5.1 and Contest Gallery Pro WordPress plugin before version 19.1.5.1 are affected by CVE-2022-4162.
What is the severity of CVE-2022-4162?
The severity of CVE-2022-4162 is medium with a CVSS score of 6.5.
How can CVE-2022-4162 be exploited?
CVE-2022-4162 can be exploited by malicious users with at least author privilege to leak sensitive information.
Are there any fixes available for CVE-2022-4162?
Yes, upgrading to version 19.1.5.1 or later of the Contest Gallery WordPress plugin and Contest Gallery Pro WordPress plugin will fix CVE-2022-4162.