What the vulnerability does
01Description
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
Explanation of Vulnerability in Simple Terms
CubeWP versions up to 1.1.30 contain a SQL injection vulnerability that allows authenticated users to read sensitive database information and disrupt site availability. An attacker with low-level access can craft malicious SQL queries through the application. The vulnerability affects the entire database, not just the vulnerable component.
What an attacker can do
Read sensitive database records and cause partial site outages.
Potential impact on your site
Unauthorized access to database contents and potential service disruption for your site.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities