CVE-2024-9828: Taskbuilder < 3.0.5 - Admin+ SQL Injection
Published Nov 21, 2024
·Updated
The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'loadorders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks
Affected Software
2 affected components
Taskbuilder Taskbuilder WordPress<3.0.5
Taskbuilder Taskbuilder WordPress plugin<3.0.5
Event History
Nov 21, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-9828?
CVE-2024-9828 has a high severity level due to its potential for SQL Injection attacks.
2
How do I fix CVE-2024-9828?
To fix CVE-2024-9828, update the Taskbuilder WordPress plugin to version 3.0.5 or later.
3
Who is affected by CVE-2024-9828?
CVE-2024-9828 affects users of the Taskbuilder WordPress plugin versions prior to 3.0.5.
4
What type of vulnerability is CVE-2024-9828?
CVE-2024-9828 is classified as an SQL Injection vulnerability.
5
Can low privilege users exploit CVE-2024-9828?
No, CVE-2024-9828 can only be exploited by high privilege users such as administrators.