Aller au contenu

Fiche vulnérabilité

CVE-2022-4290 : faille élevée cyr to lat project cyr to lat (CVSS 8.8)

Description

The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This potentially allows authenticated users with the ability to add or modify terms or tags to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A partial patch became available in version 3.6 and the issue was fully patched in version 3.7.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 oct. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • cyr to lat project cyr to lat

Références

Rechercher une autre vulnérabilité dans la base CVE