CVE-2012-5327

Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an add_user_togroup action, or (3) add_forum_group_id parameter in an add_forum_submit action.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
cartpaujmingle-forum
𝑥
≤ 1.0.32.1
cartpaujmingle-forum
1.0.00
cartpaujmingle-forum
1.0.01
cartpaujmingle-forum
1.0.02
cartpaujmingle-forum
1.0.03
cartpaujmingle-forum
1.0.04
cartpaujmingle-forum
1.0.05
cartpaujmingle-forum
1.0.06
cartpaujmingle-forum
1.0.07
cartpaujmingle-forum
1.0.08
cartpaujmingle-forum
1.0.09
cartpaujmingle-forum
1.0.10
cartpaujmingle-forum
1.0.11
cartpaujmingle-forum
1.0.12
cartpaujmingle-forum
1.0.13
cartpaujmingle-forum
1.0.14
cartpaujmingle-forum
1.0.15
cartpaujmingle-forum
1.0.16
cartpaujmingle-forum
1.0.17
cartpaujmingle-forum
1.0.18
cartpaujmingle-forum
1.0.19
cartpaujmingle-forum
1.0.20
cartpaujmingle-forum
1.0.21
cartpaujmingle-forum
1.0.21.1
cartpaujmingle-forum
1.0.22
cartpaujmingle-forum
1.0.23
cartpaujmingle-forum
1.0.23.1
cartpaujmingle-forum
1.0.23.2
cartpaujmingle-forum
1.0.24
cartpaujmingle-forum
1.0.25
cartpaujmingle-forum
1.0.26
cartpaujmingle-forum
1.0.27
cartpaujmingle-forum
1.0.28
cartpaujmingle-forum
1.0.28.1
cartpaujmingle-forum
1.0.28.2
cartpaujmingle-forum
1.0.29
cartpaujmingle-forum
1.0.30
cartpaujmingle-forum
1.0.31
cartpaujmingle-forum
1.0.31.1
cartpaujmingle-forum
1.0.31.2
cartpaujmingle-forum
1.0.31.3
cartpaujmingle-forum
1.0.31.4
cartpaujmingle-forum
1.0.32
𝑥
= Vulnerable software versions