Blind SQL Injection Vulnerability in Woocommerce Quote Calculator
CVE-2024-50479
9.8CRITICAL
Key Information
- Vendor
- Mansur Ahamed
- Status
- WooCommerce Quote Calculator
- Vendor
- CVE Published:
- 28 October 2024
Summary
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.
Affected Version(s)
Woocommerce Quote Calculator <= 1.1
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
LVT-tholv2k (Patchstack Alliance)