vendor:
cp-multi-view-calendar
by:
Joaquin Ramirez Martinez
9
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: cp-multi-view-calendar
Affected Version From: 1.1.2007
Affected Version To: 1.1.2007
Patch Exists: NO
Related CWE: N/A
CPE: a:wordpress:cp-multi-view-calendar:1.1.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2015
WordPress cp-multi-view-calendar.1.1.7 [Unauthenticated SQL injection vulnerabilities]
Multiple SQL Injection vulnerabilities has been detected in the Wordpress cp-multi-view-calendar plugin in version 1.1.7. The vulnerability allows remote attackers to inject own sql commands to compromise the affected web-application and connected dbms. The SQL Injection vulnerabilities are located in the `edit.php` and `datafeed.php` files. Remote attackers are able to inject own sql commands to the vulnerable parameters value in these files GET/POST method request.
Mitigation:
Input validation and sanitization should be used to prevent SQL injection attacks. Additionally, parameterized queries should be used to prevent SQL injection attacks.