Vulnerabilities > CVE-2022-1691 - Unspecified vulnerability in Realtyworkstation Realty Workstation

047910
CVSS 4.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
realtyworkstation

Summary

The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection

Vulnerable Configurations

Part Description Count
Application
Realtyworkstation
1