SQL Injection Vulnerability Affects Responsive Image Gallery and Gallery Album
CVE-2024-35750
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 8 June 2024
Summary
A vulnerability exists in wpdevart's Responsive Image Gallery, Gallery Album, due to improper neutralization of special elements used in SQL commands, leading to SQL Injection. This vulnerability potentially allows an attacker to manipulate database queries, which can compromise the integrity and confidentiality of data stored within the application. Versions affected range from n/a through 2.0.3, emphasizing the need for timely updates and patches to mitigate associated risks.
Affected Version(s)
Responsive Image Gallery, Gallery Album <= 2.0.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LVT-tholv2k (Patchstack Alliance)