PT-2025-1810 · Icegram Express · Email Subscribers

Dmitry Ignatyev

·

Published

2025-01-06

·

Updated

2025-01-06

·

CVE-2024-12311

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Email Subscribers by Icegram Express versions prior to 5.7.44
Description The issue concerns a SQL injection vulnerability. It occurs because a parameter is not properly sanitized and escaped before being used in a SQL statement, allowing administrators to perform SQL injection attacks.
Recommendations For versions prior to 5.7.44, update to version 5.7.44 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's SQL functionality until a patch is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-12311

Affected Products

Email Subscribers