Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0405

Опубликовано: 17 янв. 2024
Источник: nvd
CVSS3: 7.2
CVSS3: 6.5
EPSS Низкий

Описание

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This vulnerability arises due to insufficient escaping of user-supplied parameters and the lack of adequate preparation in SQL queries. As a result, authenticated attackers with editor access or higher can append additional SQL queries into existing ones, potentially leading to unauthorized access to sensitive information from the database.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:burst-statistics:burst_statistics:*:*:*:*:*:wordpress:*:*
Версия до 1.5.3 (исключая)

EPSS

Процентиль: 38%
0.00167
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 7.2
github
около 2 лет назад

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This vulnerability arises due to insufficient escaping of user-supplied parameters and the lack of adequate preparation in SQL queries. As a result, authenticated attackers with editor access or higher can append additional SQL queries into existing ones, potentially leading to unauthorized access to sensitive information from the database.

EPSS

Процентиль: 38%
0.00167
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-89
CWE-89