SQL Injection vulnerability
-
WordPress Pre* Party Resource Hints Plugin <= 1.8.18 is vulnerable to SQL Injection
https://patchstack.com/database/vulnerability/pre-party-browser-hints/wordpress-pre-party-resource-hints-plugin-1-8-18-sql-injection-vulnerability?_a_id=110
-
Any update on an upcoming patched version?
Hello.
Thank you for this great plugin. Are there any updates planned to fix this?
Looking forward to hearing from you.
The link posted above doesn’t say anything specific about where the supposed vulnerability is, or how it can be reproduced. Without that information, how am I supposed to begin fixing it?
o plugin de segurança Wordfence Security notificou esta vulnerabilidade e está recomendando desativar o seu plugin até a correção, tem alguma previsão de correção desta falha?
“SQL Injection vulnerability”
Edit: link para do wordfence
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pre-party-browser-hints/pre-party-resource-hints-1818-authenticatedadministrator-sql-injection-
This reply was modified 2 years ago by
Yui.
-
This reply was modified 2 years ago by
darlanoliveira.
Hello Sam,
If the Wordfence link does not provide enough information to help you identify the vulnerability you can always contact the researcher to help you identify the place you will need to patch.
Here is his personal website with contact info https://daffa.info/
Thank you
Hi Sam.
Wanted to pass along that wpengine is reporting the same. I dont have anymore information about the issue other then what they post here:
Hope it helps in some way.Pre* Party Resource Hints 1.8.18
- Security risk: sqli. The plugin contains a vulnerability wherein unauthenticated visitors could inject SQL statements into WordPress. SQL injection could allow an attacker to gain control of your site. Severity: medium Fixed in: no fix yet
-
This reply was modified 2 years ago by
Step By Step 3D.
-
This reply was modified 2 years ago by
Step By Step 3D.
-
This reply was modified 2 years ago by
Step By Step 3D.
Hello Sam (Plugin Author),
Thank you for your input and the valuable references shared by previous contributors, including the links to Patchstack and the reports by Muhammad Daffa. After reviewing Muhammad’s history of reporting, I’ve noticed a recurring theme of SQL Injection vulnerabilities.
Having examined some of these reports in relation to your current plugin version, I suggest focusing on the file located at
plugins/pre-party-browser-hints/includes/common/DAO.php, specifically in theget_admin_hints_querymethod, at line 140:" ORDER BY $order_by $order". It appears that this section could benefit from an update, possibly along the lines of what follows.$order_by_sql = sanitize_sql_orderby( "{$order_by} {$order}" ); $new_query['sql'] .= " ORDER BY $order_by_sql";Kind Regards,
this issue has been fixed with 1.8.19
Hi Sam,
This patch does not appear to have fixed the issue.
https://patchstack.com/database/vulnerability/pre-party-browser-hints
The vulnerability appears to be still present. The link above was last updated with the latest release 1.8.19 and still statesVulnerability history
1 present
0 patched
I’m not 100% sure this is it, but it might be worth looking at the comment I made last week to see if
sanitize_sql_orderbysanitizing the order and order by variables helps.
It might be best to reach out to the reporter to see if they can provide more information Muhammad Daffa. Alternatively, Patchstack may be able to shed some light on it [email protected].
Kind Regards,-
This reply was modified 2 years ago by
Anthony Thorne.
The Wordfence listing for this vulnerability still says it hasn’t been patched as well:
This thread was marked as resolved, but the issue still persists.
Can we get an update on when a confirmed patched version will be made available?
-
This reply was modified 2 years ago by
The topic ‘SQL Injection vulnerability’ is closed to new replies.