GHSA-pq2f-3fg3-rw99

Suggest an improvement
Source
https://github.com/advisories/GHSA-pq2f-3fg3-rw99
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-pq2f-3fg3-rw99/GHSA-pq2f-3fg3-rw99.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pq2f-3fg3-rw99
Aliases
  • CVE-2022-0254
Published
2022-03-15T00:00:57Z
Modified
2023-11-08T04:07:30.702484Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SQL Injection in WordPress Zero Spam WordPress plugin
Details

The WordPress Zero Spam WordPress plugin before 5.2.13 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

Database specific
{
    "nvd_published_at": "2022-03-14T15:15:00Z",
    "github_reviewed_at": "2022-03-29T15:26:17Z",
    "severity": "CRITICAL",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Packagist / bmarshall511/wordpress_zero_spam

Package

Name
bmarshall511/wordpress_zero_spam
Purl
pkg:composer/bmarshall511/wordpress_zero_spam

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.2.13

Affected versions

4.*

4.10.2

v5.*

v5.0.8
v5.0.12
v5.0.13
v5.1.0
v5.1.1
v5.1.2
v5.1.3
v5.1.4
v5.1.5
v5.1.6
v5.2.0
v5.2.2
v5.2.4
v5.2.5
v5.2.7
v5.2.8