First published: Fri Jun 07 2024(Updated: )
SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary SQL commands. Information stored in the database may be obtained or altered by the attacker.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Music Store | <1.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36082 is considered a high severity SQL injection vulnerability.
To fix CVE-2024-36082, update the Music Store plugin to version 1.1.14 or later.
CVE-2024-36082 affects remote authenticated users with administrative privileges on WordPress eCommerce versions prior to 1.1.14.
CVE-2024-36082 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
An attacker exploiting CVE-2024-36082 could obtain or alter information stored in the database.