CVE-2024-9186 Scanner
CVE-2024-9186 Scanner - SQL Injection vulnerability in FunnelKit Automation By Autonami
Short Info
Level
High
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
11 days 7 hours
Scan only one
Domain, IPv4, Subdomain
Toolbox
-
FunnelKit Automation By Autonami is a WordPress plugin used primarily for automating marketing workflows. It integrates seamlessly with WooCommerce, enabling users to recover abandoned carts, send newsletters, and automate email marketing campaigns. This tool is widely adopted by online stores to streamline their marketing processes and boost sales efficiency.
The vulnerability involves an SQL Injection issue present in versions of FunnelKit Automation By Autonami before 3.3.0. The plugin fails to sanitize and escape the "bwfan-track-id" parameter, leading to the potential exploitation of this flaw by malicious actors. This allows attackers to craft SQL queries, thereby gaining unauthorized access to sensitive database information.
Exploitation occurs through the "bwfan-track-id" parameter. Malicious actors can inject crafted payloads to execute time-based SQL queries. The endpoint allows unauthenticated users to perform SQL commands that manipulate or exfiltrate database records without proper authorization or validation.
If successfully exploited, attackers could compromise the integrity and confidentiality of the application's data. It may lead to unauthorized data access, leakage of sensitive information, or in some cases, disruption of the affected service's database operations.
REFERENCES