PT-2024-33564 · Unknown · Brandon White Author Discussion
João Pedro S Alcântara
·
Published
2024-10-20
·
Updated
2024-10-24
·
CVE-2024-49609
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Brandon White Author Discussion versions 0.2.2 and earlier
Description
The issue is related to an SQL Injection vulnerability, specifically a Blind SQL Injection, due to the improper neutralization of special elements used in an SQL command. This allows an attacker to potentially compromise data. The estimated number of affected devices is not specified.
Recommendations
For versions 0.2.2 and earlier, update the plugin to the latest patched version immediately to mitigate the risk of data compromise. As a temporary workaround, consider restricting access to sensitive data until the update is applied.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brandon White Author Discussion