CVE-2022-47151: WordPress JS Help Desk plugin <= 2.7.1 - Unauth. SQL Injection Vulnerability
Published Apr 17, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.
Affected Software
3 affected components
JS Help Desk JS Help Desk<=2.7.1
WordPress JS Help Desk<=2.7.1
joomsky Js Help Desk Wordpress<2.7.2
Remediation
Information
Update to 2.7.2 or a higher version.
Event History
Apr 17, 2024
CVE Published
via MITRE·10:17 AM
Data Sourced
via MITRE·10:17 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47151?
CVE-2022-47151 is classified as a critical severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2022-47151?
To mitigate CVE-2022-47151, update the JS Help Desk plugin to a version greater than 2.7.1.
3
What version of JS Help Desk is affected by CVE-2022-47151?
CVE-2022-47151 affects all versions of JS Help Desk from n/a through 2.7.1.
4
What type of vulnerability is CVE-2022-47151?
CVE-2022-47151 is an SQL injection vulnerability stemming from improper neutralization of special elements in SQL commands.
5
Is CVE-2022-47151 exploitable without authentication?
Yes, CVE-2022-47151 is an unauthenticated SQL injection vulnerability.