WordPress eDoc Easy Tables plugin <= 1.29 - CSRF to SQL Injection vulnerability
CVE-2024-53793
8.2HIGH
What is CVE-2024-53793?
A vulnerability exists in eDoc Easy Tables, a product from eDoc Intelligence LLC, which is susceptible to Cross-Site Request Forgery (CSRF). This weakness enables attackers to execute Blind SQL Injection, potentially compromising the integrity and confidentiality of the database. Affected versions span from an undefined version up to 1.29. It is essential for users of the platform to address this vulnerability promptly to prevent exploitation.
Affected Version(s)
eDoc Easy Tables <= 1.29
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)