vendor:
WP Symposium
by:
PizzaHatHacker
N/A
CVSS
N/A
SQL Injection
89
CWE
Product Name: WP Symposium
Affected Version From: ?
Affected Version To: 15.5.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:wpsymposium:wp_symposium
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache / WordPress 4.2.3 / wp-symposium 15.5.1
2015
WordPress Plugin wp-symposium Unauthenticated SQL Injection Vulnerability
Wordpress plugin wp-symposium version 15.5.1 (and probably all existing previous versions) suffers from an unauthenticated SQL Injection in get_album_item.php parameter 'size'. The issue is exploitable even if the plugin is deactivated. The SQL injection allows (very easily) to retrieve all the database content, which includes users details and password hashes. An attacker may be able to crack users' password hashes and log in as them. If an administrator user password is obtained, then the attacker could take complete control of the Wordpress installation. Collected information may also allow further attacks.
Mitigation:
The vendor has released a patch for this vulnerability. All users are advised to upgrade to the latest version of the plugin.