CVE-2022-2958observed exploitationCWE-89

CVE-2022-2958: vulnerability in BadgeOS

BadgeOS < 3.7.1.3 - Subscriber+ SQLi

Published · Updated

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 1.3%
from disclosure to weapon
Published on NVDSep 19
VulnCheck+424d
exploitation probability
1.3%top 30% of all CVEs
observed exploitation
yesVulnCheck
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
Affected products
Unknown · BadgeOS
Related CVEs — BadgeOS

In the same product, most dangerous first.