CVE-2023-2805

SupportCandy < 3.1.7 - Admin+ SQLi

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.


We have discovered 370 live websites that are affected by CVE-2023-2805.

Run a Free Instant Scan




Affected Software

Product  Supportcandy
Category Wordpress Plugins
Vulnerable Domains370 live websites (18% of Supportcandy install base)
Vulnerable Versions
  • from 0 through 3.1.7
Vulnerable Versions Count26 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jun 19, 2023
  • Updated - Dec 9, 2024

Credits

  • dc11 (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-2805
United States86 websites



Italy41 websites
Germany29 websites
Iran24 websites
Russia20 websites
GB18 websites
Brazil16 websites
France16 websites
Spain11 websites
Australia9 websites

Website Distribution by TLD

Number of websites using CVE-2023-2805
.com135 websites
.it31 websites
.ru18 websites
.com.br17 websites
.net11 websites
.org10 websites
.de8 websites
.pl6 websites
.com.au5 websites
.eu5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2805

Top websites that are affected by CVE-2023-2805. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
****************.com GB**,***
********.pt United States**,***
*****.sv El Salvador***,***
*****************.com United States***,***
***********.com United States***,***
*********.com United States***,***
*********.de Germany***,***
************.***.au Australia***,***
************.com United States***,***
See full domain list

FAQ

CVE-2023-2805 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Supportcandy
A total of 370 websites have been identified as vulnerable to CVE-2023-2805, based on global website indexing conducted by WebTechSurvey.
The Supportcandy is affected by the CVE-2023-2805 vulnerability.
Supportcandy versions up to 3.1.7 are vulnerable to CVE-2023-2805.
CVE-2023-2805 is resolved in version 3.1.7 of Supportcandy.