What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.74.
Explanation of Vulnerability in Simple Terms
02Summary
10Web Map Builder for Google Maps versions up to 1.0.74 contain a SQL injection vulnerability accessible to high-privilege users. An attacker with admin or editor access can craft malicious input to read or modify database contents. The vulnerability affects the site's database integrity and may expose sensitive information stored in the database.
What an attacker can do
03Attacker Capabilities
Read or modify database contents via SQL injection.
Potential impact on your site
04Site Impact
Database contents can be read or altered by privileged users; sensitive data exposure and data corruption are possible.
Conditions required to exploit
05Prerequisites
Attacker must have high-privilege access (admin or editor role) on the site.
Key dates
06Disclosure timeline
March 31, 2024
CVE published
April 28, 2026
Record updated