First published: Mon Jan 08 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce: from n/a through 1.5.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
UkrSolution Barcode Scanner and Inventory Manager | <=1.5.1 |
Update to 1.5.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52215 is classified as a medium severity SQL Injection vulnerability.
To fix CVE-2023-52215, update the UkrSolution Barcode Scanner and Inventory Manager plugin to version 1.5.2 or later.
Exploitation of CVE-2023-52215 can allow unauthorized users to execute arbitrary SQL commands on the database.
CVE-2023-52215 affects users of the UkrSolution Simple Inventory Management plugin version 1.5.1 and earlier.
Yes, CVE-2023-52215 can be exploited without authentication, making it particularly dangerous for vulnerable installations.