CVE-2022-3915

CVSS V2 None CVSS V3 None
Description
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
Overview
  • CVE ID
  • CVE-2022-3915
  • Assigner
  • contact@wpscan.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-12T18:15:11
  • Last Modified Date
  • 2022-12-14T21:39:06
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:wedevs:dokan:*:*:*:*:*:wordpress:*:* 1 OR 3.7.6
History
Created Old Value New Value Data Type Notes
2022-12-12 18:18:16 Added to TrackCVE
2022-12-12 19:15:55 2022-12-12T18:15:11.817 2022-12-12T18:15:11 CVE Published Date updated
2022-12-12 19:15:55 2022-12-12T18:18:02 CVE Modified Date updated
2022-12-12 19:15:55 Received Awaiting Analysis Vulnerability Status updated
2022-12-13 02:15:04 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-13 03:17:58 Undergoing Analysis Awaiting Analysis Vulnerability Status updated
2022-12-13 13:19:04 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-14 22:14:39 2022-12-14T21:39:06 CVE Modified Date updated
2022-12-14 22:14:39 Undergoing Analysis Analyzed Vulnerability Status updated
2022-12-14 22:14:39 CPE Information updated