KiviCare < 2.3.9 - Unauthenticated SQLi
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 13%
from disclosure to weapon
Published on NVDJun 13
VulnCheck+518d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users
Affected products
Unknown · KiviCare – Clinic & Patient Management System (EHR)