CVE-2024-9186 Scanner

CVE-2024-9186 Scanner - SQL Injection vulnerability in FunnelKit Automation By Autonami

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

11 days 7 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

-

FunnelKit Automation By Autonami is a WordPress plugin used primarily for automating marketing workflows. It integrates seamlessly with WooCommerce, enabling users to recover abandoned carts, send newsletters, and automate email marketing campaigns. This tool is widely adopted by online stores to streamline their marketing processes and boost sales efficiency.

The vulnerability involves an SQL Injection issue present in versions of FunnelKit Automation By Autonami before 3.3.0. The plugin fails to sanitize and escape the "bwfan-track-id" parameter, leading to the potential exploitation of this flaw by malicious actors. This allows attackers to craft SQL queries, thereby gaining unauthorized access to sensitive database information.

Exploitation occurs through the "bwfan-track-id" parameter. Malicious actors can inject crafted payloads to execute time-based SQL queries. The endpoint allows unauthenticated users to perform SQL commands that manipulate or exfiltrate database records without proper authorization or validation.

If successfully exploited, attackers could compromise the integrity and confidentiality of the application's data. It may lead to unauthorized data access, leakage of sensitive information, or in some cases, disruption of the affected service's database operations.

REFERENCES

Get started to protecting your Free Full Security Scan