CVE-2023-4797: Newsletter Lite < 4.9.3 - Admin+ Command Injection
Published Jan 16, 2024
·Updated
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
Affected Software
1 affected component
Tribulant Newsletters Wordpress<4.9.3
Event History
Jan 16, 2024
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-4797?
CVE-2023-4797 is considered a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2023-4797?
To fix CVE-2023-4797, update the Newsletters WordPress plugin to version 4.9.3 or higher.
3
What systems are affected by CVE-2023-4797?
CVE-2023-4797 affects the Newsletters WordPress plugin versions prior to 4.9.3.
4
What type of vulnerabilities are associated with CVE-2023-4797?
CVE-2023-4797 is associated with SQL injection and command injection vulnerabilities.
5
Who is impacted by CVE-2023-4797?
Administrators using vulnerable versions of the Newsletters WordPress plugin are at risk from CVE-2023-4797.