CVE-2024-55975

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Dec 18, 2024
CWE ID 89

Summary

CVE-2024-55975 is a newly disclosed SQL Injection vulnerability affecting the Dr Affiliate software version 1.2.3 and below. An attacker can exploit this weakness by injecting malicious SQL code into input fields, bypassing input validation and gaining unauthorized access to sensitive data or even executing malicious commands on the underlying database. The vulnerability occurs due to insufficient neutralization of special elements in SQL commands. Organizations using Dr Affiliate are advised to update to the latest version or apply relevant patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share