SQL injection in My Calendar - CVE-2023-6360
Published: November 30, 2023
My Calendar
Joe Dolson
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Exploitation example:
https://WORDPRESS_INSTANCE/?rest_route=/my-calendar=/my-calendar/v1/events&from=1'+AND+(SELECT+1+FROM+(SELECT(SLEEP(5)))a)+AND+'a'%3d'a