Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internet-formation
Internet-formation wp-advanced-search |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:internet-formation:wp-advanced-search:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Internet-formation
Internet-formation wp-advanced-search |
Thu, 10 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wp-advanced-search Project
Wp-advanced-search Project wp-advanced-search |
|
| CPEs | cpe:2.3:a:wp-advanced-search_project:wp-advanced-search:-:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wp-advanced-search Project
Wp-advanced-search Project wp-advanced-search |
|
| Metrics |
cvssV3_1
|
Thu, 10 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks | |
| Title | WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-10T14:54:46.206Z
Reserved: 2024-10-10T07:26:23.809Z
Link: CVE-2024-9796
Updated: 2024-10-10T14:53:08.491Z
Status : Analyzed
Published: 2024-10-10T08:15:04.140
Modified: 2024-10-15T18:46:53.397
Link: CVE-2024-9796
No data.
OpenCVE Enrichment
No data.