Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Plugin <= 2.8.2 is vulnerable to SQL Injection #46

Open
PaulSchiretz opened this issue Aug 27, 2024 · 3 comments
Open

Plugin <= 2.8.2 is vulnerable to SQL Injection #46

PaulSchiretz opened this issue Aug 27, 2024 · 3 comments

Comments

@PaulSchiretz
Copy link
Contributor

Hi @doozy @hogash @auerserg @StanMarsh @widdydev @rexwebmedia

As multiple users pointed out, it seems there is a vulnerability in the latest version 2.8.2 of the plugin.

https://patchstack.com/database/vulnerability/ti-woocommerce-wishlist/wordpress-ti-woocommerce-wishlist-plugin-2-8-2-sql-injection-vulnerability?_a_id=431

Can someone have a look at that? I tried to have a brief look in the code, but haven't discovert it on a short search, but i'm sure it might be easy to find and fix... but i don't have any means to push a new version...

Would be just great if we could keep this plugin alive!!!

Cheers,
Paul

@PaulSchiretz
Copy link
Contributor Author

I debugged the issue and found the problem, although would need some more info to provide a fix.

if you need help solving this, feel free to contact me, i'm happy to help 👋

@saimakhan77788
Copy link

i find that but now how to exploit this ? any command that help me to get that data form database

doozy added a commit that referenced this issue Oct 11, 2024
Some sanitizing against SQL injections and some minor js fix closes(#45, #46)
@doozy
Copy link
Contributor

doozy commented Oct 11, 2024

@PaulSchiretz Thank you for the pull request. I've merged it and will add other fixes related to this vulnerability

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants