SQL Injection Vulnerability in WP ERP's HR Solution
CVE-2024-0608
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 29 March 2024
What is CVE-2024-0608?
The WP ERP (Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting) for WordPress is prone to a union-based SQL Injection vulnerability. This occurs via the 'email' parameter in all versions up to and including 1.12.9. The vulnerability is attributed to insufficient escaping of user-supplied input and a lack of proper preparation in the SQL query. Authenticated attackers with subscriber-level access can exploit this flaw to inject additional SQL queries into existing ones, potentially gaining unauthorized access to sensitive database information.
Affected Version(s)
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting * <= 1.12.9