CVE-2014-1634: SQL Injection
Published Mar 9, 2020
·Updated
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/ancategoryid/ PATHINFO.
Affected Software
1 affected component
Magento Advanced Newsletter Magento<2.3.5
Event History
Mar 9, 2020
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1634?
CVE-2014-1634 is considered a critical SQL Injection vulnerability that can lead to unauthorized access to sensitive data.
2
How do I fix CVE-2014-1634?
To fix CVE-2014-1634, update the Advanced Newsletter extension to version 2.3.5 or later.
3
What types of attacks can be executed through CVE-2014-1634?
CVE-2014-1634 allows attackers to execute arbitrary SQL queries, potentially leading to data leakage or modification.
4
Which versions of the Advanced Newsletter extension are affected by CVE-2014-1634?
Versions of the Advanced Newsletter extension prior to 2.3.5 are affected by CVE-2014-1634.
5
Is the CVE-2014-1634 vulnerability common in Magento extensions?
While CVE-2014-1634 highlights a specific issue, SQL Injection vulnerabilities are a common risk in many web applications, including Magento extensions.