CVE-2024-52427: WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability
Published Nov 18, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.3.11.
Affected Software
1 affected component
Vollstart Event Tickets With Ticket Scanner Wordpress<2.3.12
Remediation
Information
Update to 2.3.12 or a higher version.
Event History
Nov 18, 2024
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52427?
CVE-2024-52427 has been classified with a high severity due to its potential for Server Side Include (SSI) Injection.
2
How do I fix CVE-2024-52427?
To fix CVE-2024-52427, upgrade the Event Tickets with Ticket Scanner plugin to version 2.3.12 or later.
3
Which versions of Event Tickets with Ticket Scanner are affected by CVE-2024-52427?
CVE-2024-52427 affects Event Tickets with Ticket Scanner versions prior to 2.3.12.
4
What type of vulnerability is CVE-2024-52427?
CVE-2024-52427 is an Improper Neutralization of Special Elements Used in a Template Engine vulnerability.
5
Can CVE-2024-52427 lead to remote code execution?
Yes, CVE-2024-52427 can potentially allow remote code execution through SSI Injection.