WordPress 插件 GamiPress 在 7.9.7 及之前版本中,wpForo 集成的 AJAX 选择器(action: )中的 'q' 参数存在已认证(订阅者及以上权限)SQL 注入漏洞。 该参数仅通过 处理后,直接以单引号包裹的 LIKE 子句形式进行字符串拼接,未使用 占位符。由于 在 WordPress 核心魔法引号处理之后执行,它会将注入的反斜杠加倍( 变为 ),导致 MySQL 将其解释为一个字面量反斜杠紧跟一个有效的结束引号,从而使攻击者能够跳出字符串边界,实现基于布尔值的 SQL 注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rubengc | GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI | 0 ~ 7.9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet