PT-2024-36627 · Unknown · Dr Affiliate

Lvt-Tholv2K

·

Published

2024-12-18

·

Updated

2024-12-18

·

CVE-2024-55975

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Dr Affiliate versions 1.2.3 and earlier
Description The issue is related to an SQL Injection vulnerability, which allows attackers to manipulate SQL commands. This is due to the improper neutralization of special elements used in an SQL command.
Recommendations For Dr Affiliate versions 1.2.3 and earlier, as a temporary workaround, consider restricting access to sensitive database operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-55975

Affected Products

Dr Affiliate