« Volver al listado

CVE-2022-2958

Estado: ModificadaAlta (8.8)—

The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2958",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "BadgeOS",
          "versions": [
            {
              "status": "affected",
              "version": "3.7.1.3",
              "lessThan": "3.7.1.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-19T14:15:11.050",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/8743534f-8ebd-496a-99bc-5052a8bac86a",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/8743534f-8ebd-496a-99bc-5052a8bac86a",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "contact@wpscan.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections"
    },
    {
      "lang": "es",
      "value": "El plugin BadgeOS de WordPress versiones anteriores a 3.7.1.3, no sanea ni escapa de los parámetros antes de usarlos en sentencias SQL por medio de  acciones AJAX disponibles para cualquier usuario autenticado, lo que conlleva inyecciones SQL"
    }
  ],
  "lastModified": "2026-06-17T04:42:53.160",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:badgeos:badgos:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB50DB2A-AC5E-4596-B079-E78D9134A378",
              "versionEndExcluding": "3.7.1.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}