Description
mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Andrea Bocchetti
References
www.exploit-db.com/exploits/45330 (ExploitDB-45330)
addons.moosocial.com/stores (Reference)
moosocial.com/product/store-plugins/ (Official Product Homepage)
www.vulncheck.com/...gin-sql-injection-via-product-parameter (VulnCheck Advisory: mooSocial Store Plugin 2.6 SQL Injection via product parameter)