vendor:
Arigato Autoresponder and Newsletter
by:
Larry W. Cashdollar
4.8
CVSS
MEDIUM
Blind SQL injection and multiple reflected XSS
89, 79, 79, 79, 79, 79, 79, 79, 79, 79
CWE
Product Name: Arigato Autoresponder and Newsletter
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: YES
Related CWE: CVE-2018-1002000, CVE-2018-1002001, CVE-2018-1002002, CVE-2018-1002003, CVE-2018-1002004, CVE-2018-1002005, CVE-2018-1002006, CVE-2018-1002007, CVE-2018-1002008, CVE-2018-1002009
CPE: a:kiboko_labs:arigato_autoresponder_and_newsletter
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
Blind SQL injection and multiple reflected XSS vulnerabilities in WordPress Plugin Arigato Autoresponder and Newsletter v2.5
This plugin allows scheduling of automated autoresponder messages and newsletters, and managing a mailing list. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request. Nine Reflected XSS vulnerabilities exist in lines 22-23, 28, 29, 30, 31, 32, 33, 34, and 35 of controllers/list.php and bft_list.html.php respectively.
Mitigation:
Administrative privileges are required to exploit these vulnerabilities. The vendor has released a fixed version (v2.5.1.5) to address these issues.