cve/2022/CVE-2022-1472.md

18 lines
744 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-1472](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1472)
![](https://img.shields.io/static/v1?label=Product&message=Better%20Find%20and%20Replace&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.3.6%3C%201.3.6%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-89%20SQL%20Injection&color=brighgreen)
### Description
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
### POC
#### Reference
- https://wpscan.com/vulnerability/9c608b14-dc5e-469e-b97a-84696fae804c
#### Github
No PoCs found on GitHub currently.