The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-04T20:02:29.849Z
Reserved: 2023-04-17T09:57:53.143Z
Link: CVE-2023-2114
Updated: 2024-08-02T06:12:20.188Z
Status : Modified
Published: 2023-05-08T14:15:13.507
Modified: 2025-02-04T20:15:46.647
Link: CVE-2023-2114
No data.
OpenCVE Enrichment
No data.
Weaknesses