PT-2024-35013 · Unknown · Gboy Custom Google Map

Lvt-Tholv2K

·

Published

2024-11-10

·

Updated

2024-11-15

·

CVE-2024-51882

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Gboy Custom Google Map versions n/a through 1.2
Description The issue is related to an SQL Injection vulnerability, specifically an Improper Neutralization of Special Elements used in an SQL Command. This allows for Blind SQL Injection, which could lead to security breaches and potentially grants an attacker full database access. It is recommended to patch immediately and check for any compromise.
Recommendations For versions n/a through 1.2, patch immediately to prevent potential security breaches. As a temporary workaround, consider restricting access to sensitive database elements until a patch is applied. Avoid using user-input data directly in SQL commands to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-51882

Affected Products

Gboy Custom Google Map