7.5

CVE-2021-24295

Exploit

Time-based Blind SQL Injection in Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4

Spam protection, AntiSpam, FireWall by CleanTalk <= 5.153.3 - Unauthenticated Blind SQL Injection

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.
Mögliche Gegenmaßnahme
CleanTalk Anti-Spam. Spam Firewall & Bot protection: Update to version 5.153.4, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CleantalkSpam Protection, Antispam, Firewall SwPlatformwordpress Version < 5.153.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt CleanTalk Anti-Spam. Spam Firewall & Bot protection
Version *-5.153.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.69% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://wpscan.com/vulnerability/152171fc-888c-4275-a118-5a1e664ef28b
Third Party Advisory
https://www.wordfence.com/blog/2021/05/sql-injection-vulnerability-patched-in-cleantalk-antispam-plugin/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/7fe50510-6736-4bcf-b62f-0b8d2cb8ff3a
Third Party Advisory