CVE-2020-5766
srs_simple_hits_counter_project srs_simple_hits_counter Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2020-5766 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
SRS Simple Hits Counter Plugin for WordPress | CVE List | 1.0.3, 1.0.4 | affected |
srs_simple_hits_counterBrowse srs_simple_hits_counter_project / srs_simple_hits_counter | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHSRS Simple Hits Counter 1.0.3-1.0.4 - Unauthenticated Blind SQL InjectionCVSS 7.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.
Impact
Unauthenticated attackers can extract database contents via blind SQL injection, potentially exposing sensitive WordPress user data and credentials.
Remediation
Update to the latest version of SRS Simple Hits Counter plugin.
Source: ProjectDiscovery