vendor:
iThemes Security
by:
Çlirim Emini
8.8
CVSS
HIGH
Authenticated SQL Injection
89
CWE
Product Name: iThemes Security
Affected Version From: 7.0.2 and below
Affected Version To: 7.0.2 and below
Patch Exists: YES
Related CWE: 2018-12636
CPE: a:ithemes:better-wp-security
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
WordPress Plugin iThemes Security(better-wp-security) <= 7.0.2 - Authenticated SQL Injection
WordPress Plugin iThemes Security(better-wp-security) before 7.0.3 allows remote authenticated users to execute arbitrary SQL commands via the 'orderby' parameter in the 'itsec-logs' page to wp-admin/admin.php. Parameter orderby is vulnerable because backend variable $sort_by_column is not escaped.
Mitigation:
Upgrade to version 7.0.3 or later.