PT-2024-21157 · Unknown · Cd Custom Fields 4 Orders

Published

2024-03-07

·

Updated

2024-08-27

·

CVE-2024-25845

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CD Custom Fields 4 Orders version 1.0.0 and earlier
Description A SQL injection issue exists, allowing a guest to perform malicious actions.
Recommendations For versions 1.0.0 and earlier, update to a version later than 1.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the module "CD Custom Fields 4 Orders" to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-25845

Affected Products

Cd Custom Fields 4 Orders