PT-2025-2908 · Unknown · Clickwhale

Trương Hữu Phúc

·

Published

2025-01-07

·

Updated

2025-06-09

·

CVE-2024-51715

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages versions n/a through 2.4.1
Description The issue is related to an Improper Neutralization of Special Elements used in an SQL Command, also known as a SQL Injection vulnerability, which allows Blind SQL Injection. This means that an attacker could potentially inject malicious SQL code into the application's database, leading to unauthorized access or modification of data.
Recommendations For ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages versions n/a through 2.4.1, update to a version later than 2.4.1 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-51715

Affected Products

Clickwhale