CVE-2024-0399
HIGHWooCommerce Customers Manager < 29.7 - Authenticated SQL Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-0399. PoCs published by Ivan Spiridonov, xbz0n.
AI-analyzed exploit summary This PoC demonstrates a time-based SQL injection vulnerability in WooCommerce Customers Manager 29.4 via the 'max_amount_total' parameter in an admin AJAX endpoint. The exploit uses a sleep-based payload to confirm the vulnerability.
Description
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
Exploits (2)
This PoC demonstrates a time-based SQL injection vulnerability in WooCommerce Customers Manager 29.4 via the 'max_amount_total' parameter in an admin AJAX endpoint. The exploit uses a sleep-based payload to confirm the vulnerability.
This repository provides a functional proof-of-concept for CVE-2024-0399, demonstrating a time-based SQL injection vulnerability in WooCommerce Customers Manager 29.4 via the 'max_amount_total' parameter in an admin AJAX endpoint. The PoC includes a detailed HTTP request that triggers a 20-second delay, confirming the vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N