PT-2024-17219 · WordPress · Kivicare

Khayal Farzaliyev

+1

·

Published

2024-12-06

·

Updated

2024-12-06

·

CVE-2024-11730

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress versions prior to 3.6.5
Description The issue is related to SQL injection through the sort[] parameter of the "static data list" AJAX action. This vulnerability is due to insufficient escaping of the user-supplied parameter and lack of sufficient preparation in the existing SQL query. Authenticated attackers with doctor/receptionist-level access and above can append additional SQL queries to existing ones, allowing them to extract sensitive information from the database.
Recommendations For versions prior to 3.6.5, update to version 3.6.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the static data list AJAX action to minimize the risk of exploitation. Avoid using the sort[] parameter in the affected AJAX endpoint until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11730

Affected Products

Kivicare