GHSA-6f58-v6v9-pjm9HighCVSS 8.2
WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection...
🔗 CVE IDs covered (1)
📋 Description
WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the space_id parameter. Attackers can send GET requests to the booking-page endpoint with malicious space_id values using AND SLEEP() payloads to extract sensitive database information.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2017-20243
- https://codecanyon.net/item/car-park-booking-wordpress-plugin/20284035
- https://www.exploit-db.com/exploits/43012
- https://www.vulncheck.com/advisories/wordpress-car-park-booking-plugin-sql-injection-via-space-id
- https://github.com/advisories/GHSA-6f58-v6v9-pjm9