Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-0566. PoCs published by Ivan Spiridonov, xbz0n.
AI-analyzed exploit summary This is a proof-of-concept for a time-based SQL injection vulnerability in Smart Manager 8.27.0, exploiting unsanitized sorting parameters in an admin AJAX endpoint. The PoC demonstrates a 20-second delay via SQL injection, confirming the vulnerability.
Description
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Exploits (2)
This is a proof-of-concept for a time-based SQL injection vulnerability in Smart Manager 8.27.0, exploiting unsanitized sorting parameters in an admin AJAX endpoint. The PoC demonstrates a 20-second delay via SQL injection, confirming the vulnerability.
The repository provides a functional proof-of-concept for a time-based SQL injection vulnerability in Smart Manager 8.27.0, exploiting unsanitized sorting parameters in an admin AJAX endpoint. The PoC includes a detailed HTTP request demonstrating the exploit.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H