The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
History

Tue, 15 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
CPEs cpe:2.3:a:templateinvaders:ti_woocommerce_wishlist:*:*:*:*:free:wordpress:*:*

Thu, 10 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Templateinvaders
Templateinvaders ti Woocommerce Wishlist
CPEs cpe:2.3:a:templateinvaders:ti_woocommerce_wishlist:*:*:*:*:*:wordpress:*:*
Vendors & Products Templateinvaders
Templateinvaders ti Woocommerce Wishlist
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Oct 2024 06:15:00 +0000

Type Values Removed Values Added
Description The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection via lang parameters
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-10-10T06:00:03.691Z

Updated: 2024-10-10T15:06:35.948Z

Reserved: 2024-09-24T15:42:31.039Z

Link: CVE-2024-9156

cve-icon Vulnrichment

Updated: 2024-10-10T15:00:46.931Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-10T06:15:11.290

Modified: 2024-10-15T14:40:45.093

Link: CVE-2024-9156

cve-icon Redhat

No data.