PT-2024-15687 · WordPress · Piraeus Bank Woocommerce Payment Gateway

Francesco Carlucci

·

Published

2024-02-17

·

Updated

2024-02-20

·

CVE-2024-0610

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Piraeus Bank WooCommerce Payment Gateway plugin for WordPress versions up to, and including, 1.6.5.1
Description The issue is related to a time-based blind SQL Injection vulnerability via the MerchantReference parameter. This vulnerability is caused by insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query, allowing unauthenticated attackers to append additional SQL queries into already existing queries. This can be used to extract sensitive information from the database.
Recommendations For versions up to, and including, 1.6.5.1, update to a version later than 1.6.5.1 to resolve the issue. As a temporary workaround, consider restricting access to the MerchantReference parameter to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-0610

Affected Products

Piraeus Bank Woocommerce Payment Gateway