First published: Tue Jan 23 2024(Updated: )
SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webkul Bundle Product | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51210 is considered a critical SQL injection vulnerability.
To fix CVE-2023-51210, update the Webkul Bundle Product plugin to the latest version available.
The potential impacts of CVE-2023-51210 include unauthorized remote code execution and data manipulation.
CVE-2023-51210 affects Webkul Bundle Product version 6.0.1.
Yes, CVE-2023-51210 can be exploited by remote attackers without requiring authentication.