PT-2024-4027 · WordPress · Masterstudy Lms Wordpress Plugin

Krzysztof Zając

·

Published

2024-02-17

·

Updated

2024-12-18

·

CVE-2024-1512

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MasterStudy LMS WordPress Plugin versions up to, and including, 3.2.5
Description: The issue is related to a union-based SQL Injection vulnerability via the user parameter of the "/lms/stm-lms/order/items" REST route. This vulnerability is caused by insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query, making it possible for unauthenticated attackers to append additional SQL queries into already existing queries. This can be used to extract sensitive information from the database.
Recommendations: For MasterStudy LMS WordPress Plugin versions up to, and including, 3.2.5, update the plugin to a version later than 3.2.5 to resolve the issue. As a temporary workaround, consider restricting access to the "/lms/stm-lms/order/items" REST route to minimize the risk of exploitation. Additionally, ensure proper validation and sanitization of user input to prevent similar issues in the future.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04463
CVE-2024-1512

Affected Products

Masterstudy Lms Wordpress Plugin