CVE-2024-55975
CVSS 3.1 Score 8.5 of 10 (high)
Details
Summary
CVE-2024-55975 is a newly disclosed SQL Injection vulnerability affecting the Dr Affiliate software version 1.2.3 and below. An attacker can exploit this weakness by injecting malicious SQL code into input fields, bypassing input validation and gaining unauthorized access to sensitive data or even executing malicious commands on the underlying database. The vulnerability occurs due to insufficient neutralization of special elements in SQL commands. Organizations using Dr Affiliate are advised to update to the latest version or apply relevant patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.