CVE-2024-56039
CVSS 3.1 Score 9.3 of 10 (high)
Details
Published Dec 31, 2024
CWE ID 89
Summary
CVE-2024-56039 is a newly disclosed SQL Injection vulnerability affecting VibeBP, a component of VibeThemes. The flaw stems from the improper neutralization of special elements used in SQL commands. Attackers can exploit this vulnerability to execute malicious SQL queries and gain unauthorized access to sensitive data. This issue poses a serious threat to websites using VibeBP versions prior to 1.9.9.7.7. It is crucial that users update their VibeBP instances to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.