668
VMScore

CVE-2017-12199

Published: 02/08/2017 Updated: 03/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item, custom_fields_update_order field-item, categories_update_order category-item, subcategories_update_order subcategory-item, and tags_update_order tag-list-item.

Vulnerable Product Search on Vulmon Subscribe to Product

etoilewebdesign ultimate product catalog 4.2.11

Github Repositories

cve

I want to get a cve CVE-2017-12068 CVE-2017-12131 CVE-2017-12199 CVE-2017-12200