PT-2024-39484 · Unknown · Seur Plugin
Ángel Heredia Pérez
+1
·
Published
2024-10-10
·
Updated
2024-10-16
·
CVE-2024-9201
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SEUR plugin versions prior to 2.5.11
Description
The SEUR plugin is vulnerable to time-based SQL injection through the use of the
id order parameter of the "/modules/seur/ajax/saveCodFee.php" endpoint. This issue affects versions prior to 2.5.11.Recommendations
For versions prior to 2.5.11, update to version 2.5.11 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "/modules/seur/ajax/saveCodFee.php" endpoint until a patch is available.
Avoid using the
id order parameter in the affected endpoint until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seur Plugin