First published: Mon Nov 18 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Post SMTP allows Blind SQL Injection.This issue affects Post SMTP: from n/a through 2.9.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpexperts Post SMTP | <=2.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52436 has a high severity rating due to its potential for Blind SQL Injection.
To fix CVE-2024-52436, update Post SMTP to version 2.9.10 or later.
CVE-2024-52436 affects Post SMTP versions up to and including 2.9.9.
CVE-2024-52436 allows attackers to perform Blind SQL Injection attacks.
Yes, a patch is available in Post SMTP version 2.9.10 and later.