Blind SQL Injection Vulnerability in Pinpoint Booking System
CVE-2024-53815

8.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
6 December 2024

Summary

A security vulnerability exists within the Pinpoint Booking System provided by PINPOINT.WORLD, characterized as an SQL Injection flaw. This vulnerability allows attackers to execute unapproved SQL commands through input fields, potentially leading to unauthorized access to sensitive data. Affected versions include those from n/a to 2.9.9.5.1. It is crucial for users and administrators of the Pinpoint Booking System to implement mitigations promptly to safeguard against potential exploitation.

Affected Version(s)

Pinpoint Booking System <= 2.9.9.5.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.