
CVE-2023-41507 Una password hardcoded in Super Store Finder v3.6 consente agli aggressori di accedere al pannello di amministrazione.
CVE-2023-41507 - È stato scoperto che Super Store Finder v3.6 contiene molteplici vulnerabilità di SQL injection nel componente store locator tramite i parametri products, distance, lat e lng.
SQL Injection
Super Store Finder - Versione interessata 3.6 o inferiore. Corretta nella versione 3.7
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (10.0)
DBMS backend interessato
Remoto
true
I 4 parametri products, distance, lat, lng nella richiesta HTTP POST sono vulnerabili a SQL Injection; non è richiesta alcuna interazione con l'utente.
Screenshot dell'indicatore di SQL injection basata su errori

Screenshot della Proof-of-Concept per estrarre la tabella users tramite SQLMap

https://superstorefinder.net/support/forums/topic/super-store-finder-patch-notes/