vendor:
Booking Calendar
by:
B0UG
8.8
CVSS
HIGH
Authenticated SQL Injection
89
CWE
Product Name: Booking Calendar
Affected Version From: Tested on version 8.4.3 (older versions may also be affected)
Affected Version To: Tested on version 8.4.3 (older versions may also be affected)
Patch Exists: YES
Related CWE: CVE-2018-20556
CPE: a:wpbookingcalendar:booking_calendar
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
WordPress Booking Calendar v8.4.3 – Authenticated SQL Injection Vulnerability
An authenticated SQL Injection vulnerability in the 'Booking Calendar' WordPress plugin allows an attacker to read arbitrary data from the database. An attacker can perform a time based SQL injection by appending ) AND SLEEP(100) AND (1=1 after the ID value in the parameter. Obtaining a shell using sqlmap can be done by using the --sql-shell, --os-shell, and --os-cmd options.
Mitigation:
The vendor has released a patch to address the vulnerability. It is recommended to update the plugin to the latest version.