SQL Injection Vulnerability in Cost Of Goods
CVE-2024-53783
7.6HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 30 November 2024
Summary
An SQL Injection vulnerability exists within the Anzia Ni WooCommerce Cost Of Goods plugin, allowing attackers to execute arbitrary SQL commands through improperly sanitized user inputs. This security flaw affects all versions of the plugin from unspecified to version 3.2.8, potentially compromising the integrity and security of the databases associated with the affected sites. Administrators using this plugin should promptly assess the security of their installations to prevent exploitation.
Affected Version(s)
Ni WooCommerce Cost Of Goods <= 3.2.8
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Hakiduck (Patchstack Alliance)