PT-2024-33571 · Unknown · Nyasro Rate Own Post

João Pedro S Alcântara

·

Published

2024-10-20

·

Updated

2024-10-22

·

CVE-2024-49616

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nyasro Rate Own Post versions from n/a through 1.0
Description The issue is related to an SQL Injection vulnerability, specifically an Improper Neutralization of Special Elements used in an SQL Command. This allows for Blind SQL Injection, which can be exploited.
Recommendations For Nyasro Rate Own Post versions from n/a through 1.0, consider disabling any functionality that allows user input to be executed as SQL commands until a patch is available. Restrict access to sensitive database elements to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-49616

Affected Products

Nyasro Rate Own Post