CVE-2024-51579
CVSS 3.1 Score 8.5 of 10 (high)
Details
Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 89
Summary
CVE-2024-51579 is a newly identified SQL injection vulnerability affecting the 5 Stars Rating Funnel component of Saleswonder.Biz. The issue stems from a lack of neutralization of special elements in SQL commands, making it possible for attackers to inject malicious queries. This vulnerability poses a risk to Saleswonder.Biz users with versions ranging from n/a to 1.4.01, potentially allowing unauthorized access to sensitive data or the ability to modify or delete critical information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.