Record summary

CVE-2022-0658 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

CommonsBooking

CVE List2.6.8 to < 2.6.8affected

Nuclei templates

1
ProjectDiscoveryCRITICALCommonsBooking < 2.6.8 - SQL InjectionCVSS 9.8

The plugin does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection.

Impact

Unauthenticated attackers can execute SQL injection via unsanitized AJAX parameters to extract database contents, potentially exposing sensitive WordPress data including user credentials.

Remediation

Fixed in version 2.6.8

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022wordpresswp-pluginwpcommonsbookingsqliwpscanwielebenwirvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wielebenwir:commonsbooking:*:*:*:*:*:wordpress:*:*
Google: inurl:/wp-content/plugin/commonsbooking/

Source: ProjectDiscovery

References

2