← back
CVE-2022-0592observed exploitationCWE-89

MapSVG < 6.2.20 - Unauthenticated SQLi

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 10%
from disclosure to weapon
Published on NVDMay 9
VulnCheck+623d
exploitation probability
10%top 5% of all CVEs
observed exploitation
yesVulnCheck
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
Affected products
Unknown · MapSVG