Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based blind or time-based blind SQL injection payloads to extract sensitive database information.
Metrics
Affected Vendors & Products
References
History
Sat, 16 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based blind or time-based blind SQL injection payloads to extract sensitive database information. | |
| Title | WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via sidx | |
| First Time appeared |
Supsystic
Supsystic ultimate Maps |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:supsystic:ultimate_maps:1.1.12:*:*:*:*:*:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.10:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.11:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.12:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.13:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.14:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.15:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.16:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.7:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.8:*:*:*:*:wordpress:*:* cpe:2.3:a:supsystic:ultimate_maps:1.2.9:*:*:*:*:wordpress:*:* |
|
| Vendors & Products |
Supsystic
Supsystic ultimate Maps |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-16T15:25:57.854Z
Reserved: 2026-05-15T15:04:26.823Z
Link: CVE-2020-37242
No data.
Status : Received
Published: 2026-05-16T16:16:20.487
Modified: 2026-05-16T16:16:20.487
Link: CVE-2020-37242
No data.
OpenCVE Enrichment
Updated: 2026-05-16T17:00:13Z