PT-2024-4027 · WordPress · Masterstudy Lms Wordpress Plugin
Krzysztof Zając
·
Published
2024-02-17
·
Updated
2024-12-18
·
CVE-2024-1512
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MasterStudy LMS WordPress Plugin versions up to, and including, 3.2.5
Description:
The issue is related to a union-based SQL Injection vulnerability via the
user parameter of the "/lms/stm-lms/order/items" REST route. This vulnerability is caused by insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query, making it possible for unauthenticated attackers to append additional SQL queries into already existing queries. This can be used to extract sensitive information from the database.Recommendations:
For MasterStudy LMS WordPress Plugin versions up to, and including, 3.2.5, update the plugin to a version later than 3.2.5 to resolve the issue. As a temporary workaround, consider restricting access to the "/lms/stm-lms/order/items" REST route to minimize the risk of exploitation. Additionally, ensure proper validation and sanitization of user input to prevent similar issues in the future.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Masterstudy Lms Wordpress Plugin