PT-2024-33564 · Unknown · Brandon White Author Discussion

João Pedro S Alcântara

·

Published

2024-10-20

·

Updated

2024-10-24

·

CVE-2024-49609

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brandon White Author Discussion versions 0.2.2 and earlier
Description The issue is related to an SQL Injection vulnerability, specifically a Blind SQL Injection, due to the improper neutralization of special elements used in an SQL command. This allows an attacker to potentially compromise data. The estimated number of affected devices is not specified.
Recommendations For versions 0.2.2 and earlier, update the plugin to the latest patched version immediately to mitigate the risk of data compromise. As a temporary workaround, consider restricting access to sensitive data until the update is applied.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-49609

Affected Products

Brandon White Author Discussion