Security readout for executives and security teams
Plain-English summary
CVE-2022-40403 is a reported SQL injection flaw in Wedding Planner v1.0. A privileged administrator request to an edit page may allow database compromise if the application builds SQL unsafely from the id parameter. The official affected-product metadata is incomplete, so exposure depends on whether this exact application or derived code is deployed.
Executive priority
Treat as high priority only if this niche application is present. The main business risk is administrator-path database compromise, potentially affecting event, customer, or operational data. If not deployed, no direct action is indicated beyond confirming inventory.
Technical view
The CVE describes CWE-89 SQL injection through the id parameter at /admin/feature_edit.php in Wedding Planner v1.0. CVSS 3.1 is 7.2, reflecting network reachability, low attack complexity, high privileges required, no user interaction, and high confidentiality, integrity, and availability impact. No official patch information is present in the provided sources.
Likely exposure
Most exposure is likely limited to organizations running Wedding Planner v1.0 or reused source code, especially where the admin interface is internet-accessible. The CVE metadata does not identify a vendor, package, CPE, or deployment footprint.
Exploitation context
The CVE is not listed as CISA KEV in the provided bundle, and no cited source states active exploitation. The public reference appears to be a vulnerability report, which may increase researcher awareness but does not prove real-world attacks.
Researcher notes
Evidence is thin: the CVE description and one public report identify the vulnerable endpoint and parameter, but affected-product metadata is mostly n/a. High privileges are required per CVSS, so validation should focus on admin exposure, code review, and whether forks inherited the same handler.
Mitigation direction
- Confirm whether Wedding Planner v1.0 or derived code is deployed.
- Check the maintainer or vendor channel for fixed release guidance.
- Restrict access to the admin interface until remediation is confirmed.
- If maintaining the code, replace unsafe SQL construction with parameterized queries.
- Review database accounts used by the application for least privilege.
Validation and detection
- Inventory web assets for Wedding Planner v1.0 and derived copies.
- Check whether /admin/feature_edit.php exists and is externally reachable.
- Review id parameter handling for unsafe SQL string construction.
- Check logs for unusual admin requests targeting feature_edit.php.
- Confirm remediation with regression tests around id parameter handling.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupDatabase behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2022-40403 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.2 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H1.25.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.2HighVector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/wshark00/Bug_report/blob/main/vendors/pushpam02/wedding-planner/SQLi-3.mdCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
