PT-2024-33564 · Unknown · Brandon White Author Discussion

·

CVE-2024-49609

·

Published

2024-10-20

·

Updated

2024-10-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brandon White Author Discussion versions 0.2.2 and earlier
Description The issue is related to an SQL Injection vulnerability, specifically a Blind SQL Injection, due to the improper neutralization of special elements used in an SQL command. This allows an attacker to potentially compromise data. The estimated number of affected devices is not specified.
Recommendations For versions 0.2.2 and earlier, update the plugin to the latest patched version immediately to mitigate the risk of data compromise. As a temporary workaround, consider restricting access to sensitive data until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-49609

Affected Products

Brandon White Author Discussion