The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
Metrics
Affected Vendors & Products
References
History
Tue, 20 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress |
|
CPEs | cpe:2.3:a:smartsearchwp:chatbot_with_chatgpt_wordpress:*:*:*:*:*:*:*:* | |
Vendors & Products |
Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress |
|
Metrics |
cvssV3_1
|
Tue, 20 Aug 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot. | |
Title | SmartSearch WP <= 2.4.4 - Unauthenticated SQLi | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-08-20T06:00:03.192Z
Updated: 2024-08-20T18:50:30.236Z
Reserved: 2024-07-17T18:48:10.771Z
Link: CVE-2024-6847
Vulnrichment
Updated: 2024-08-20T18:50:25.304Z
NVD
Status : Awaiting Analysis
Published: 2024-08-20T06:15:05.470
Modified: 2024-08-20T19:35:15.040
Link: CVE-2024-6847
Redhat
No data.