nuclei-templates icon indicating copy to clipboard operation
nuclei-templates copied to clipboard

Added CVE-2024-1207 template

Open Monst3rSec opened this issue 11 months ago • 3 comments

Booking Calendar <= 9.9 - Unauthenticated SQL Injection

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

  • References:
    • https://www.wordfence.com/threat-intel/vulnerabilities/id/7802ed1f-138c-4a3d-916c-80fb4f7699b2?source=cve
    • https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3032596%40booking&new=3032596%40booking&sfp_email=&sfph_mail=

Template Validation

cve-2024-1207

I've validated this template locally?

  • [x] YES
  • [ ] NO

Additional Details (leave it blank if not applicable)

Additional References:

Monst3rSec avatar Mar 23 '24 09:03 Monst3rSec

Thanks for your contribution @Monst3rSec , we really appreciate it!

GeorginaReeder avatar Mar 25 '24 09:03 GeorginaReeder

Hello @Monst3rSec,

Thank you for sharing the template with us. We appreciate the effort you have put into creating it. However, at the moment we cannot add templates that detect vulnerabilities based on version detection. Please update the template with a working exploit.

Thank you for understanding.

ritikchaddha avatar Mar 26 '24 05:03 ritikchaddha

Hi @DhiyaneshGeek,

Due to the unavailability of a reliable working exploit, reproducing the issue has become difficult. Therefore, I have opted to validate the CVE-2024-1207 by conducting version checks.

I kindly request the collaboration of both the community and the nuclei team in addressing this template.

Thanks.

Monst3rSec avatar Apr 14 '24 17:04 Monst3rSec