漏洞描述
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/8acc0fc6-efe6-4662-b9ac-6342a7823328/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-3142↗packetstormsecurity.comhttp://packetstormsecurity.com/files/171477/WordPress-NEX-Forms-SQL-Injection.html↗medium.comhttps://medium.com/%40elias.hohl/authenticated-sql-injection-vulnerability-in-nex-forms-wordpress-plugin-35b8558dd0f5↗