SQL Injection Vulnerability in Fluent Support
CVE-2024-47304

8.5HIGH

Key Information:

Vendor
WPmanageninja Llc
Status
Fluent Support
Vendor
CVE Published:
17 October 2024

Summary

A vulnerability affecting the Fluent Support plugin by WPManageNinja LLC enables SQL Injection due to improper neutralization of special elements used in SQL commands. This flaw allows attackers to manipulate the database query structure, potentially leading to unauthorized access to sensitive data. The affected versions range from n/a up to 1.8.0, necessitating an immediate update to protect against exploitation and safeguard user data against unauthorized access.

Affected Version(s)

Fluent Support <= 1.8.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khalid Yusuf (Patchstack Alliance)
.