WordPress security changelog
MEDIUM CVE-2014-4944 Modified

Bsk Pdf Manager: SQL injection

Bsk Pdf Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

CVE / CNA score 6.5 CVSS · cve@mitre.org
NVD score 6.5 CVSS 2.0 · nvd@nist.gov
Component
Bsk Pdf Manager
Plugin slug
bsk-pdf-manager
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Jul 14, 2014
Weakness
CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

This CVE was published Jul 14, 2014 and is one of 7 known issues for this plugin.

Patch or disable the affected component.

Update Bsk Pdf Manager to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.

NVD vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Primary and upstream sources