CVE-2022-0814
Ubigeo de Peru < 3.6.4 - Unauthenticated SQLi
Record summary
CVE-2022-0814 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Ubigeo de Perú para Woocommerce y WordPress | CVE List | 3.6.4 to < 3.6.4 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALUbigeo de Peru < 3.6.4 - SQL InjectionCVSS 9.8
The plugin does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections.
Impact
Unauthenticated attackers can exploit SQL injection via AJAX actions to extract usernames and password hashes from the WordPress database.
Remediation
Fixed in version 3.6.4
Source: ProjectDiscovery