Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3142


The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.


Published

2022-09-19T14:15:11.357

Last Modified

2024-11-21T07:18:54.867

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application basixonline nex-forms < 7.9.7 Yes

References