mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-31 10:40:54 +00:00
21 lines
980 B
Markdown
21 lines
980 B
Markdown
### [CVE-2022-0783](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0783)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/4d594424-8048-482d-b61c-45be1e97a8ba
|
|
- https://wpscan.com/vulnerability/4d594424-8048-482d-b61c-45be1e97a8ba
|
|
|
|
#### Github
|
|
- https://github.com/20142995/sectool
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/cyllective/CVEs
|
|
|