vendor:
Wow Forms
by:
TAD GROUP
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Wow Forms
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:wow-company:wow_forms:2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Wow Forms v2.1 WordPress Plugin SQL Injection
An unescaped parameter was found in Wow Forms v2.1 (WP plugin). An attacker can exploit this vulnerability to read from the database. The POST parameter 'wowformid' is vulnerable.
Mitigation:
Ensure that user input is properly sanitized and escaped before being used in a SQL query.