CVE-2023-2744: WP ERP < 1.12.4 - Admin+ SQL Injection
Published Jun 27, 2023
·Updated
The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the type parameter in the erp/v1/accounting/v1/people REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Affected Software
1 affected component
weDevs Wp Erp Wordpress<1.12.4
Event History
Jun 27, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-2744.
2
What is the severity of CVE-2023-2744?
The severity of CVE-2023-2744 is high.
3
What is the affected software?
The affected software is the ERP WordPress plugin before version 1.12.4.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by high privilege users, such as admin, through a SQL injection in the `type` parameter of the `erp/v1/accounting/v1/people` REST API endpoint.
5
Is there a fix available for CVE-2023-2744?
Yes, the fix for CVE-2023-2744 is to update the ERP WordPress plugin to version 1.12.4 or later.