cleantalk
Vulnerabilities and Security Researches

Directory Listings WordPress plugin – uListing, e52f7971-d8ef-49eb-8c2b-4b42d97fc9aa

Published on
-
Research Description
Directory Listings WordPress plugin &#8211; uListing [ulisting] < 1.7 uListing &lt; 1.7 - Unauthenticated SQL Injections The /1/api/ulisting-page-statistics/listing REST route did not sanitise or escape the listing_id and user_id GET parameters before using them in a SQL statement, leading to an SQL Injection issue. The plugin also did not sanitise and escape the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR which are then used in a SQL statement. As these can be spoofed/forged, unauthenticated users could perform SQL Injection
Affected versions
max 1.7.
Status
vulnerable