Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-45912 | Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11. | 
Fixes
    Solution
Update to 2.3.12 or a higher version.
Workaround
No workaround given by the vendor.
References
        History
                    Wed, 20 Nov 2024 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Vollstart
         Vollstart event Tickets With Ticket Scanner  | 
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:vollstart:event_tickets_with_ticket_scanner:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | 
        
        Vollstart
         Vollstart event Tickets With Ticket Scanner  | 
Tue, 19 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Saso Nikolov
         Saso Nikolov event Tickets With Ticket Scanner  | 
|
| CPEs | cpe:2.3:a:saso_nikolov:event_tickets_with_ticket_scanner:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Saso Nikolov
         Saso Nikolov event Tickets With Ticket Scanner  | 
|
| Metrics | 
        
        ssvc
         
  | 
Mon, 18 Nov 2024 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11. | |
| Title | WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability | |
| Weaknesses | CWE-1336 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2024-11-19T14:42:17.964Z
Reserved: 2024-11-11T06:39:29.556Z
Link: CVE-2024-52427
Updated: 2024-11-18T21:48:21.892Z
Status : Analyzed
Published: 2024-11-18T15:15:06.657
Modified: 2024-11-20T15:29:52.547
Link: CVE-2024-52427
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD