OnionBuzz, CVE-2019-14231
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jul 22, 2019
- Research Description
- An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.
- Affected versions
-
Min -, max 1.2.2.
- Status
-
vulnerable
Previous vulnerability researches |
---|
OnionBuzz (CVE-2025-53312) , Jul 03, 2025 |
OnionBuzz (CVE-2019-14231) , Jun 07, 2024 |
OnionBuzz (CVE-2019-14230) , Jun 07, 2024 |