CVE-2023-2114: NEX-Forms < 8.4 - Admin+ SQL Injection
Published May 8, 2023
·Updated
The NEX-Forms WordPress plugin before 8.4 does not properly escape the table parameter, which is populated with user input, before concatenating it to an SQL query.
Affected Software
1 affected component
Basixonline Nex-forms Wordpress<8.4
Event History
May 8, 2023
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
DescriptionWeakness
Data Sourced
02:15 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-2114?
CVE-2023-2114 has a high severity level due to its potential for SQL injection attacks.
2
How do I fix CVE-2023-2114?
To fix CVE-2023-2114, update the NEX-Forms WordPress plugin to version 8.4 or later.
3
What consequences can result from exploiting CVE-2023-2114?
Exploiting CVE-2023-2114 can lead to unauthorized access to the database and manipulation of sensitive data.
4
Which versions of NEX-Forms are affected by CVE-2023-2114?
CVE-2023-2114 affects all versions of NEX-Forms prior to version 8.4.
5
Is CVE-2023-2114 a known SQL injection vulnerability?
Yes, CVE-2023-2114 is classified as an SQL injection vulnerability due to improper input handling.