CVE-2022-0479

CVE-2022-0479: Popup Builder < 4.1.1 - SQL Injection to Reflected Cross-Site Scripting

Vendor Unknown
Product Popup Builder – Create highly converting, mobile friendly marketing popups.
Weakness CWE-89 · SQLi
Published March 28, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

Key dates

02Disclosure timeline

March 28, 2022 CVE published
August 2, 2024 Record updated