What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
Explanation of Vulnerability in Simple Terms
Fusion Builder versions up to 3.11.1 contain a SQL injection vulnerability in a database query that does not properly sanitize user input. An authenticated user with low privileges can craft a malicious request to extract sensitive data from the site's database or disrupt database operations. The vulnerability affects multiple users and components due to scope change.
What an attacker can do
Extract sensitive data from the database or cause database errors and service disruption.
Potential impact on your site
Unauthorized access to database contents including user data, posts, and configuration; potential site downtime.
Conditions required to exploit
Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities