Web / CMS

SQL / NoSQL Injection

Elementor Website Builder <= 3.10.0 - Admin+ SQLi

Elementor Website Builder <= 3.10.0 – Admin+ SQLi The plugin does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL

7.2
/ 10
High
CVSS v3.1
ADVISORY ID
PS67
PUBLISHED
2023-06-19
CVE IDs
CVE-2023-0329
VENDORS
Elementor
PUBLIC EXPLOIT
PoC public
CWE
CWE-89
PRODUCT
Elementor Website Builder (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Elementor Website Builder <= 3.10.0 – Admin+ SQLi

The plugin does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

Vulnerability details

Vulnerability details

CVE-2023-0329
CWE-89
High | 7.2

Elementor Website Builder <= 3.10.0 – Admin+ SQLi The plugin does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

Auth:
Administrative privileges (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2023-01-20 Reported On

2023-05-02 Made Public On

2023-05-01 Fixed On

Credits

Sanjay Das