NA

CVE-2022-45808

Published: 26/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thimpress learnpress

Github Repositories

LearnPress Plugin < 4.2.0 - Unauthenticated SQLi

CVE-2022-45808 LearnPress Plugin &lt; 420 - Unauthenticated time-based blind SQLi Description The plugin does not properly sanitise and escape the order by parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users POC $ python sqlmappy -u 'wordpresslan:80/wp-json/lp/v1/courses/archive-course' --data=&#