What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
Explanation of Vulnerability in Simple Terms
WishList Member X versions before 3.26.7 contain a SQL injection vulnerability in the database query handling. An attacker can inject malicious SQL commands through user input without authentication. This allows complete compromise of the site database, including reading sensitive data, modifying records, and disrupting service. All sites running affected versions should update immediately.
What an attacker can do
Read, modify, or delete any data in the site database without logging in.
Potential impact on your site
Complete database compromise: user credentials, payment info, and all site data at risk.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities