CVE-2024-36082: SQL Injection
Published Jun 7, 2024
·Updated
SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary SQL commands. Information stored in the database may be obtained or altered by the attacker.
Affected Software
1 affected component
CodePeople Music Store Wordpress<1.1.14
Event History
Jun 7, 2024
CVE Published
via MITRE·03:42 AM
Data Sourced
via MITRE·03:42 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36082?
CVE-2024-36082 is considered a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-36082?
To fix CVE-2024-36082, update the Music Store plugin to version 1.1.14 or later.
3
Who is affected by CVE-2024-36082?
CVE-2024-36082 affects remote authenticated users with administrative privileges on WordPress eCommerce versions prior to 1.1.14.
4
What type of vulnerability is CVE-2024-36082?
CVE-2024-36082 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
5
What could an attacker achieve with CVE-2024-36082?
An attacker exploiting CVE-2024-36082 could obtain or alter information stored in the database.