lenonleite.com.br
http://lenonleite.com.br/en/2016/12/16/zm-gallery-1-plugin-wordpress-blind-injection CVE-2016-10940
HIGHNuclei
WordPress zm-gallery plugin 1.0 SQL Injection
Record summary
CVE-2016-10940 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWordPress zm-gallery plugin 1.0 SQL InjectionCVSS 7.2
zm-gallery plugin 1.0 for WordPress is susceptible to SQL injection via the order parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Update to the latest version of the zm-gallery plugin or apply the patch provided by the vendor.
WeaknessesCWE-89
Authorscckuailong, daffainfo
Template tagscvecve2016wpscansqliwpwordpresswp-pluginauthenticatedzm-gallery_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:zm-gallery_project:zm-gallery:1.0:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/c0cbd314-0f4f-47db-911d-9b2e974bd0f6 https://lenonleite.com.br/en/2016/12/16/zm-gallery-1-plugin-wordpress-blind-injection/ https://nvd.nist.gov/vuln/detail/CVE-2016-10940 http://lenonleite.com.br/en/2016/12/16/zm-gallery-1-plugin-wordpress-blind-injection/ https://wordpress.org/plugins/zm-gallery/#developers
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-10940 wordpress.org
https://wordpress.org/plugins/zm-gallery