CVE-2024-5522: HTML5 Video Player < 2.5.27 - Unauthenticated SQLi
Published Jun 20, 2024
·Updated
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Affected Software
2 affected components
bPlugins Html5 Video Player Wordpress<2.5.27
WordPress HTML5 Video Player<2.5.27
Event History
Jun 20, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5522?
CVE-2024-5522 is classified with a high severity due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-5522?
To fix CVE-2024-5522, update the HTML5 Video Player plugin to version 2.5.27 or later.
3
Who is affected by CVE-2024-5522?
CVE-2024-5522 affects WordPress sites using the HTML5 Video Player plugin version before 2.5.27.
4
What type of attack can be performed using CVE-2024-5522?
CVE-2024-5522 allows unauthenticated users to execute SQL injection attacks due to improper input handling.
5
Are there any known exploits for CVE-2024-5522?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2024-5522.