vendor:
IrisAccess iCAM4000/iCAM7000
by:
Security Affairs
9,8
CVSS
CRITICAL
Use of Hardcoded Credentials
287
CWE
Product Name: IrisAccess iCAM4000/iCAM7000
Affected Version From: iCAM4000: iCAM Software: 3.09.02, iCAM File system: 1.3, CMR Firmware: 5.5 and 3.8, EIF Firmware: 9.5 and 8.0, HID iClass Library: 2.01.05, ImageData Library: 1.153, Command Process: 1.02
Affected Version To: iCAM7000: iCAM Software: 8.01.07, iCAM File system: 1.4.0, EIF Firmware: 1.9, HID iClass Library: 1.00.00, ImageData Library: 01.01.32, EyeSeek Library: 5.00, Countermeasure Library: 3.00, LensFinder Library: 5.00, Tilt Assist Library: 4.00
Patch Exists: YES
Related CWE: CVE-2020-14092
CPE: o:iris_id:irisaccess_icam4000_icam7000
Metasploit:
N/A
Other Scripts:
N/A
Tags: wp-plugin,sqli,paypal,wpscan,cve,cve2020,wordpress
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'framework': 'wordpress', 'vendor': 'ithemes', 'product': 'paypal_pro'}
Platforms Tested: None
2020
Iris ID IrisAccess iCAM4000/iCAM7000 Hardcoded Credentials Remote Shell Access
WordPress PayPal Pro plugin before 1.1.65 is susceptible to SQL injection via the 'query' parameter which allows for any unauthenticated user to perform SQL queries with the results output to a web page in JSON format.
Mitigation:
Users should update to the latest version of the Iris ID IrisAccess iCAM4000/7000 series.