CVE-2023-2805: SupportCandy < 3.1.7 - Admin+ SQLi
Published Jun 19, 2023
·Updated
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the setaddagentleaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Affected Software
1 affected component
SupportCandy SupportCandy WordPress<3.1.7
Event History
Jun 19, 2023
CVE Published
via MITRE·10:52 AM
Data Sourced
via MITRE·10:52 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-2805.
2
What is the severity of CVE-2023-2805?
The severity of CVE-2023-2805 is high with a severity value of 7.2.
3
What is the affected software for CVE-2023-2805?
The affected software for CVE-2023-2805 is the SupportCandy WordPress plugin before version 3.1.7.
4
What is the description of CVE-2023-2805?
CVE-2023-2805 is a SQL injection vulnerability in the SupportCandy WordPress plugin, allowing high privilege users to exploit it.
5
How can I fix CVE-2023-2805?
To fix CVE-2023-2805, you should update the SupportCandy WordPress plugin to version 3.1.7 or later.