First published: Thu Nov 28 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Distance Based Shipping Calculator allows SQL Injection.This issue affects Distance Based Shipping Calculator: from n/a through 2.0.21.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Distance Based Shipping Calculator | <=2.0.21 | |
WordPress Distance Based Shipping Calculator Plugin | <=2.0.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52495 is classified as a high severity SQL Injection vulnerability in Eniture Technology Distance Based Shipping Calculator.
To fix CVE-2024-52495, update the Eniture Technology Distance Based Shipping Calculator to version 2.0.22 or later.
CVE-2024-52495 affects all versions of Distance Based Shipping Calculator up to and including 2.0.21.
CVE-2024-52495 allows attackers to perform SQL Injection attacks, which can lead to unauthorized data access or manipulation.
CVE-2024-52495 specifically affects the Distance Based Shipping Calculator plugin used in WordPress.