.. / CVE-2022-0785

Exploit for WordPress Daily Prayer Time <2022.03.01 - SQL Injection (CVE-2022-0785)

Description:

WordPress Daily Prayer Time plugin prior to 2022.03.01 contains a SQL injection vulnerability.. It does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action, available to unauthenticated users, leading to SQL injection.

Nuclei Template

View the template here CVE-2022-0785.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0785.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-0785
https://wpscan.com/vulnerability/e1e09f56-89a4-4d6f-907b-3fb2cb825255
https://github.com/ARPSyndicate/cvemon
https://wordpress.org/plugins/daily-prayer-time-for-mosques/
https://github.com/20142995/sectool