CVE-2024-9186
Automation By Autonami < 3.3.0 - Unauthenticated SQLi
Record summary
CVE-2024-9186 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKitDefault status: unaffected | CVE List | Before 3.3.0 | affected |
funnelkit_automationsBrowse funnelkit / funnelkit_automationsDefault status: unknown | CVE List | Before 3.3.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHAutomation By Autonami < 3.3.0 - SQL InjectionCVSS 8.6
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
Impact
Unauthenticated attackers can exploit time-based SQL injection through the bwfan-track-id parameter to extract sensitive database information including user credentials, email addresses, WooCommerce customer data, and marketing automation information.
Remediation
Fixed in 3.3.0
Source: ProjectDiscovery