Fiche vulnérabilité
CVE-2022-2754 : faille critique ketchup restaurant reservations… (CVSS 9.8)
Description
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 sept. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ketchup restaurant reservations project ketchup restaurant reservations