Unrated severityNVD Advisory· Published May 30, 2022· Updated Aug 3, 2024
StaffList < 3.1.5 - Admin+ SQLi
CVE-2022-1556
Description
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection
Affected products
1- Range: 3.1.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- packetstormsecurity.com/files/166918/mitrex_refsource_MISC
- wpscan.com/vulnerability/04890549-6bd1-44dd-8bce-7125c01be5d4mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.