漏洞描述
WordPress WPSmartContracts plugin before 1.3.12 contains a SQL injection vulnerability. The plugin does not properly sanitize and escape a parameter before using it in a SQL statement. An attacker with a role as low as author can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/1d8bf5bb-5a17-49b7-a5ba-5f2866e1f8a3↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3768↗cve.reporthttps://cve.report/CVE-2022-3768↗bulletin.iese.dehttps://bulletin.iese.de/post/wp-smart-contracts_1-3-11/↗github.comhttps://github.com/ARPSyndicate/cvemon↗