Lucene search

K
wpvulndbKhanhWPVDB-ID:02C5E10C-1AC7-447E-8AE5-B6D251BE750B
HistoryNov 02, 2020 - 12:00 a.m.

AccessPress Social Icons < 1.8.1 - Authenticated SQL Injection

2020-11-0200:00:00
khanh
wpscan.com
4
accesspress social icons
sql injection
widget attribute
post permission
author
sanitisation

EPSS

0.001

Percentile

37.0%

The plugin does not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

PoC

https://drive.google.com/file/d/1UBTpW3RcPR7iqTi94ueyXLwWH8aFHuoe/view?usp=sharing Payload: [aps-social id=“1 and sleep(3)”]

EPSS

0.001

Percentile

37.0%

Related for WPVDB-ID:02C5E10C-1AC7-447E-8AE5-B6D251BE750B