CVE-2022-45808
Description
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CWE
- CWE-89 — CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected
- ThimPress / LearnPress – WordPress LMS Plugin — v=n/a ≤4.1.7.3.2 [affected]
CVSS
- 3.1 score=9.9 severity=CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
References
- https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-wordpress-lms-plugin-plugin-4-1-7-3-2-sql-injection?_s_id=cve vdb-entry
- https://patchstack.com/articles/multiple-critical-vulnerabilities-fixed-in-learnpress-plugin-version/ technical-description
Source
cvelistV5-main/cves/2022/45xxx/CVE-2022-45808.json