First published: Thu Oct 06 2016(Updated: )
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Portfolio Gallery | =1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1000124 has been rated as a critical vulnerability due to its potential for unauthenticated SQL injection.
To fix CVE-2016-1000124, update the Huge-IT Portfolio Gallery Plugin to version 1.0.7 or later, which includes patches for this vulnerability.
CVE-2016-1000124 allows attackers to perform unauthenticated SQL injection attacks, potentially leading to data exposure and unauthorized access to the database.
Only Huge-IT Portfolio Gallery Plugin version 1.0.6 is affected by CVE-2016-1000124.
Yes, CVE-2016-1000124 is exploitable remotely since it involves unauthenticated access to the system.