CVE-2024-53815: WordPress Pinpoint Booking System plugin <= 2.9.9.5.2 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Blind SQL Injection.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53815?
CVE-2024-53815 is classified as a high-severity vulnerability due to its potential for blind SQL injection attacks.
How do I fix CVE-2024-53815?
To fix CVE-2024-53815, update the Pinpoint Booking System or the WordPress Pinpoint Booking System plugin to the latest version beyond 2.9.9.5.2.
What versions are affected by CVE-2024-53815?
CVE-2024-53815 affects all versions of the Pinpoint Booking System up to and including 2.9.9.5.1 and the WordPress Pinpoint Booking System plugin up to and including 2.9.9.5.2.
What types of attacks can CVE-2024-53815 enable?
CVE-2024-53815 can enable blind SQL injection attacks, allowing attackers to manipulate databases without direct feedback.
Is user data at risk with CVE-2024-53815?
Yes, due to the nature of SQL injection attacks, user data can be compromised if CVE-2024-53815 is exploited.