What the vulnerability does
01Description
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
Explanation of Vulnerability in Simple Terms
Sticky Chat Widget versions up to 1.4.2 contain a SQL injection vulnerability in how the plugin processes user input. An attacker on the network can craft malicious requests to read sensitive data from the site's database without needing to log in or interact with a user. The vulnerability also impacts system availability.
What an attacker can do
Read sensitive data from the site's database, including user information and configuration details.
Potential impact on your site
Attackers can extract database contents, exposing user data and site configuration without your knowledge.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities