CVE-2024-6809: Simple Video Directory < 1.4.3 - Unauthenticated SQLi
The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6809?
CVE-2024-6809 has a severity rating that indicates it poses a risk of SQL injection due to improper sanitization of parameters.
How do I fix CVE-2024-6809?
To remediate CVE-2024-6809, update the Simple Video Directory plugin to version 1.4.3 or later.
Who is affected by CVE-2024-6809?
Users of the Simple Video Directory WordPress plugin prior to version 1.4.3 are affected by CVE-2024-6809.
Can unauthenticated users exploit CVE-2024-6809?
Yes, CVE-2024-6809 can be exploited by unauthenticated users through an AJAX action.
What type of vulnerability is CVE-2024-6809?
CVE-2024-6809 is a SQL injection vulnerability that can compromise the database through lack of proper input sanitization.