SQL Injection Vulnerability Affects Contest Gallery
CVE-2024-30236
9.9CRITICAL
What is CVE-2024-30236?
The Contest Gallery plugin by Patchstack is vulnerable due to improper neutralization of special elements used in SQL commands, commonly known as SQL injection. This vulnerability can allow attackers to manipulate queries, potentially exposing sensitive data or executing arbitrary SQL commands. Versions affected range from its initial release up to and including version 21.3.4, making it crucial for users to assess their version and apply necessary patches to mitigate the risk.
Affected Version(s)
Contest Gallery <= 21.3.4