vendor:
WatuPRO
by:
Manich Koomsusi
9,8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: WatuPRO
Affected Version From: 5.5.1
Affected Version To: 5.5.1
Patch Exists: YES
Related CWE: CVE-2017-9834
CPE: a:calendarscripts:watupro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress 4.7.5
2017
SQL Injection In WatuPRO (WordPress Plugin to Create Exams, Tests and Quizzes)
SQL Injection in WatuPRO WordPress Plugin for create exams, Tests and Quizzes allow the attacker dump the database contents. This plugin sending quizzes to the server with “watupro_questions” parameter not sanitize before take SQL statement.
Mitigation:
Sanitize the input before taking SQL statement.