VDB
CVE-2023-0037
CVE-2023-0037
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
EPSS 3.91% · 89.8th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.91%
89.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | 10Web Map Builder for Google Maps | 0 |
| 10web | map_builder_for_google_maps | 0 |
Timeline
- Mar 3, 2023 VulnCheck KEV Exploitation
- Mar 13, 2023 CVE Published
- Mar 14, 2023 EPSS Score
- May 31, 2023 EPSS Score
- Jul 9, 2023 EPSS Score
- Sep 24, 2023 EPSS Score
- Nov 2, 2023 EPSS Score
- Jan 19, 2024 EPSS Score
- Apr 6, 2024 EPSS Score
- May 14, 2024 EPSS Score
- Jul 31, 2024 EPSS Score
- Oct 17, 2024 EPSS Score