What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes VibeBP vibebp allows SQL Injection.This issue affects VibeBP: from n/a through < 1.9.9.5.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes VibeBP vibebp allows SQL Injection.This issue affects VibeBP: from n/a through < 1.9.9.5.1.
Explanation of Vulnerability in Simple Terms
VibeBP versions up to 1.9.9.5.1 contain a SQL injection vulnerability in a database query that requires low-level authentication to exploit. An attacker with a user account can craft malicious input to read sensitive data from the database or disrupt site availability. The vulnerability affects multiple users and components due to scope change.
What an attacker can do
Read sensitive database records and cause partial site unavailability.
Potential impact on your site
User data and site configuration may be exposed; site performance may degrade.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities