SQL Injection Vulnerability in MORKVA Shipping Plugin for Nova Poshta
CVE-2025-24612
9.3CRITICAL
What is CVE-2025-24612?
An SQL Injection vulnerability has been identified in the MORKVA Shipping for Nova Poshta plugin, allowing attackers to craft malicious SQL queries. This weakness potentially permits unauthorized access to the database, enabling data manipulation and exposure. It is essential for users of the plugin, particularly those on versions up to 1.19.6, to apply security measures and updates to safeguard their systems.
Affected Version(s)
Shipping for Nova Poshta 0 <= 1.19.6
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)