mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-12-16 10:44:41 +00:00
60 lines
2.0 KiB
JSON
60 lines
2.0 KiB
JSON
{
|
|
"id": "CVE-2025-23911",
|
|
"sourceIdentifier": "audit@patchstack.com",
|
|
"published": "2025-01-16T21:15:32.780",
|
|
"lastModified": "2025-01-16T21:15:32.780",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solidres Team Solidres \u2013 Hotel booking plugin allows SQL Injection.This issue affects Solidres \u2013 Hotel booking plugin: from n/a through 0.9.4."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": " Vulnerabilidad de neutralizaci\u00f3n incorrecta de elementos especiales utilizados en un comando SQL ('Inyecci\u00f3n SQL') en Solidres Team Solidres \u2013 Hotel booking plugin permite inyecci\u00f3n SQL. Este problema afecta a Solidres \u2013 Hotel booking plugin: desde n/a hasta 0.9.4."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "audit@patchstack.com",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
|
|
"baseScore": 8.5,
|
|
"baseSeverity": "HIGH",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "LOW",
|
|
"userInteraction": "NONE",
|
|
"scope": "CHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "LOW"
|
|
},
|
|
"exploitabilityScore": 3.1,
|
|
"impactScore": 4.7
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "audit@patchstack.com",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-89"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://patchstack.com/database/wordpress/plugin/solidres/vulnerability/wordpress-solidres-hotel-booking-plugin-for-wordpress-plugin-0-9-4-sql-injection-vulnerability?_s_id=cve",
|
|
"source": "audit@patchstack.com"
|
|
}
|
|
]
|
|
} |