Vulnerabilities > CVE-2022-1684 - Unspecified vulnerability in Webpsilon Cube Slider 1.0/1.1/1.2

047910
CVSS 2.7 - LOW
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
webpsilon

Summary

The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin

Vulnerable Configurations

Part Description Count
Application
Webpsilon
4