Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through 0.2.2.
History

Thu, 24 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Brandonwhite
Brandonwhite author Discussion
CPEs cpe:2.3:a:brandonwhite:author_discussion:*:*:*:*:*:wordpress:*:*
Vendors & Products Brandonwhite
Brandonwhite author Discussion

Mon, 21 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Oct 2024 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through 0.2.2.
Title WordPress Author Discussion plugin <= 0.2.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-10-20T10:02:22.291Z

Updated: 2024-10-21T19:18:05.792Z

Reserved: 2024-10-17T09:51:09.447Z

Link: CVE-2024-49609

cve-icon Vulnrichment

Updated: 2024-10-21T19:18:00.394Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-20T10:15:03.860

Modified: 2024-10-24T15:25:17.023

Link: CVE-2024-49609

cve-icon Redhat

No data.