What the vulnerability does
01Description
Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.
Explanation of Vulnerability in Simple Terms
RSVPMaker versions before 10.5.5 contain a SQL injection vulnerability in database queries. An attacker with high-level privileges can craft malicious input to read sensitive data from the database. The vulnerability affects the broader application scope and may cause service disruption. Update to version 10.5.5 or later to remediate.
What an attacker can do
Read sensitive data from the database and cause service disruption.
Potential impact on your site
Unauthorized database access and potential data exposure if an admin account is compromised or misused.
Conditions required to exploit
Attacker must have high-level administrative or privileged account access to the application.
Key dates
External resources
Related vulnerabilities