CVE-2022-0592

CVE-2022-0592: MapSVG < 6.2.20 - Unauthenticated SQLi

Vendor Unknown
Product MapSVG
Weakness CWE-89 · SQLi
Published May 9, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

Key dates

02Disclosure timeline

May 9, 2022 CVE published
August 2, 2024 Record updated