漏洞描述
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
woocommerce.comhttps://woocommerce.com/posts/critical-vulnerability-detected-july-2021↗viblo.asiahttps://viblo.asia/p/phan-tich-loi-unauthen-sql-injection-woocommerce-naQZRQyQKvx↗securitynews.sonicwall.comhttps://securitynews.sonicwall.com/xmlpost/wordpress-woocommerce-plugin-sql-injection/↗wpscan.comhttps://wpscan.com/vulnerability/0f2089dc-9376-4d7d-95a2-25c99526804a↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-32789↗