CVE-2024-10499: AI-Engine < 2.6.5 - Admin+ SQLi
Published Dec 12, 2024
·Updated
The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
2 affected components
AI Engine WordPress plugin<2.6.5
Meowapps Ai Engine Wordpress<2.6.5
Event History
Dec 12, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-10499?
CVE-2024-10499 has been rated as high severity due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-10499?
To fix CVE-2024-10499, update the AI Engine WordPress plugin to version 2.6.5 or later.
3
Who is affected by CVE-2024-10499?
CVE-2024-10499 affects users of the AI Engine WordPress plugin prior to version 2.6.5.
4
What kind of attack can result from CVE-2024-10499?
CVE-2024-10499 allows attackers to perform SQL injection attacks through an unsanitized parameter.
5
When was CVE-2024-10499 disclosed?
CVE-2024-10499 was disclosed along with its impact on the AI Engine WordPress plugin in 2024.