PT-2022-21932 · Unknown · Wp All Export Pro
Sanjay Das
·
Published
2022-10-25
·
Updated
2022-10-26
·
CVE-2022-3395
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP All Export Pro versions prior to 1.7.9
Description
The issue allows users with permission to run exports to execute arbitrary SQL statements due to the direct use of the
cc sql POST parameter as a database query. This affects users who have been given permission to perform exports, which by default includes only users with the Administrator role, but can also include lower privileged users if such permissions are delegated.Recommendations
For versions prior to 1.7.9, update to version 1.7.9 or later to resolve the issue. As a temporary workaround, consider restricting the permission to run exports to only the Administrator role until the update is applied.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp All Export Pro