Vulnerability Details CVE-2018-7474
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.179
EPSS Ranking 94.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-7474
-
cpe:2.3:a:textpattern:textpattern:1.0
-
cpe:2.3:a:textpattern:textpattern:4.0.0
-
cpe:2.3:a:textpattern:textpattern:4.0.1
-
cpe:2.3:a:textpattern:textpattern:4.0.2
-
cpe:2.3:a:textpattern:textpattern:4.0.3
-
cpe:2.3:a:textpattern:textpattern:4.0.4
-
cpe:2.3:a:textpattern:textpattern:4.0.5
-
cpe:2.3:a:textpattern:textpattern:4.0.6
-
cpe:2.3:a:textpattern:textpattern:4.0.7
-
cpe:2.3:a:textpattern:textpattern:4.0.8
-
cpe:2.3:a:textpattern:textpattern:4.2.0
-
cpe:2.3:a:textpattern:textpattern:4.3.0
-
cpe:2.3:a:textpattern:textpattern:4.4.0
-
cpe:2.3:a:textpattern:textpattern:4.4.1
-
cpe:2.3:a:textpattern:textpattern:4.5.0
-
cpe:2.3:a:textpattern:textpattern:4.5.1
-
cpe:2.3:a:textpattern:textpattern:4.5.2
-
cpe:2.3:a:textpattern:textpattern:4.5.4
-
cpe:2.3:a:textpattern:textpattern:4.5.5
-
cpe:2.3:a:textpattern:textpattern:4.5.7
-
cpe:2.3:a:textpattern:textpattern:4.6.0
-
cpe:2.3:a:textpattern:textpattern:4.6.1
-
cpe:2.3:a:textpattern:textpattern:4.6.2