CVE-2023-3077
MStore API < 3.9.8 - Unauthenticated Blind SQLi
Record summary
CVE-2023-3077 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MStore APIDefault status: unaffected | CVE List | Before 3.9.8 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALMStore API < 3.9.8 - SQL InjectionCVSS 9.8
The MStore API WordPress plugin before 3.9.8 is vulnerable to Blind SQL injection via the product_id parameter.
Impact
Allows an attacker to extract sensitive data from the database
Remediation
Update MStore API WordPress Plugin to the latest version to mitigate the vulnerability
Source: ProjectDiscovery