CVE-2024-1061: SQL Injection
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'getview' function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1061?
CVE-2024-1061 is considered a critical severity vulnerability due to its potential for unauthenticated SQL injection.
How do I fix CVE-2024-1061?
To fix CVE-2024-1061, upgrade the 'HTML5 Video Player' WordPress Plugin to version 2.5.25 or later.
What type of attack can exploit CVE-2024-1061?
CVE-2024-1061 can be exploited through an unauthenticated SQL injection attack targeting the 'id' parameter in the 'get_view' function.
Who is affected by CVE-2024-1061?
Users of the 'HTML5 Video Player' WordPress Plugin versions earlier than 2.5.25 are affected by CVE-2024-1061.
What functionality is impacted by CVE-2024-1061?
CVE-2024-1061 impacts the ability of the plugin to handle requests securely, potentially exposing database information.