vendor:
Ultimate Maps
by:
Erik David Martin
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Ultimate Maps
Affected Version From: 1.1.12
Affected Version To: 1.1.12
Patch Exists: YES
Related CWE: N/A
CPE: a:supsystic:ultimate_maps:1.1.12
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: 16.04.6 LTS / WordPress 5.4.2
2020
WordPress Plugin Supsystic Ultimate Maps 1.1.12 – ‘sidx’ SQL injection
The GET parameter 'sidx' does not sanitize user input when searching for existing maps. An attacker can use ZAP/Burp to capture the web request when searching for existing maps and save it to request.txt. Then, they can use sqlmap to exploit the vulnerability.
Mitigation:
Upgrade to version 1.1.13 or later.