漏洞描述
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitize, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL injection issue.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
codevigilant.comhttps://codevigilant.com/disclosure/2021/wp-plugin-cars-seller-auto-classifieds-script-sql-injection/↗wpscan.comhttps://wpscan.com/vulnerability/f35d6ab7-dd52-48b3-a79c-3f89edf24162↗codevigilant.comhttps://codevigilant.com/disclosure/2021/24-04-2021-wp-plugin-cars-seller-auto-classifieds-script-sql-injection/↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/SexyBeast233/SecBooks↗