CVE-2024-6723: AI Engine < 2.4.8 - Admin+ SQLi
Published Sep 13, 2024
·Updated
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
Affected Software
1 affected component
Meowapps Ai Engine Wordpress<2.4.8
Event History
Sep 13, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-6723?
CVE-2024-6723 is a critical vulnerability that allows SQL injection due to improper sanitization in the AI Engine WordPress plugin.
2
How do I fix CVE-2024-6723?
To fix CVE-2024-6723, upgrade the AI Engine WordPress plugin to version 2.4.8 or later.
3
Who is affected by CVE-2024-6723?
Admin users of the AI Engine WordPress plugin versions prior to 2.4.8 are at risk of CVE-2024-6723.
4
What type of vulnerability is CVE-2024-6723?
CVE-2024-6723 is classified as a SQL injection vulnerability.
5
Can CVE-2024-6723 be exploited remotely?
CVE-2024-6723 is exploitable by admin users when viewing chatbot discussions within the WordPress dashboard.