First published: Fri Jan 20 2023(Updated: )
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Survey Maker | <3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-23490.
The title of the vulnerability is 'The Survey Maker WordPress Plugin version < 3.1.2 is affected by an authenticated SQL injection vulnerability'.
The affected software is the Survey Maker WordPress Plugin version < 3.1.2.
The severity of the vulnerability is high with a CVSS score of 8.8.
Yes, the vulnerability is publicly disclosed and can be found at https://www.tenable.com/security/research/tra-2023-2.
The Common Weakness Enumeration (CWE) ID is 89.
The vulnerability allows authenticated users to perform SQL injection attacks by manipulating the 'surveys_ids' parameter of the 'ays_surveys_export_json' action.
Update the Survey Maker WordPress Plugin to version 3.1.2 or later, as this version contains a fix for the vulnerability.