Record summary

CVE-2019-20361 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits, 1 repository PoC, and 2 curated repository PoCs.

Description

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2
Repository PoCs
1
Curated repository PoCs
2

Proofs of concept

5

Catalogued exploits

ExploitDBWordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)ExploitDB exploitby KBA@SOGETI_ESECNot analyzed1 file
ExploitDB

PoC details
MetasploitWordPress Email Subscribers and Newsletter Hash SQLi ScannerMetasploit auxiliary PoCby Wordfence +2 moreNot analyzed1 file

Ruby

Metasploit

PoC details

Curated repository PoCs

GitHubCVE-2019-20361-EXPLOITCurated repository PoCby 0xd3vilStars: 127Not analyzed2 files

Python · 8.0 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubCVE-2019-20361-EXPLOITCurated repository PoCby yubsyStars: 112Not analyzed2 files

Python · 8.0 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Repository PoCs

GitHubjerrylewis9/CVE-2019-20361-EXPLOITRepository PoCby jerrylewis9Stars: 0Not analyzed2 files

8.0 KiB

GitHub

PoC details

References

4