Popular WordPress Plugin Exposes Database to Attack
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
To exploit a site, one of two scenarios must be available to an attacker. The first would require an authenticated user account to exploit the tag gallery short code to inject the exploit. The second requires a NextGEN Basic TagCloud gallery to be used on the site allowing an unauthenticated remote user to inject the exploit using a slightly modified gallery URL.
The latest version of NextGEN Gallery plugin is free from this vulnerability.
Further Technical details:
The vulnerability discovered is a SQL injection type where user input is not correctly sanitised specifically for $container_ids which is created from the tag input.
PHP vsprintf function is used to pass the statement as a format string and the input is passed as value arguments, which are used to sanitise the input removing the immediate danger of a SQL injection. However, the tag input is passed directly into the format string allowing sprintf/printf directives to be passed.
With no sanitation against these directives, the intended action can be controlled. This vulnerability comes into play during the WordPress database abstraction prepare() method where changes are performed on the SQL code. An apostrophe is added after any %s string it finds and passes it through the vsprintf, processing any format strings injected. If carefully crafted, it can be used to alter the SQL query return causing united queries to be run on the backend database that can include sensitive user data.
Remediation steps
Last edited: 17 February 2020 11:37 am