First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yannick Lefebvre Bug Library allows Blind SQL Injection. This issue affects Bug Library: from n/a through 2.1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Yannick Lefebvre Bug Library | <=2.1.4 | |
WordPress Bug Library Plugin | <=2.1.4 |
Update the WordPress Bug Library wordpress plugin to the latest available version (at least 2.1.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24728 is classified as a high severity vulnerability due to its potential for blind SQL injection.
To fix CVE-2025-24728, update the Yannick Lefebvre Bug Library to version 2.1.5 or later.
CVE-2025-24728 affects Yannick Lefebvre Bug Library versions up to and including 2.1.4 as well as the WordPress Bug Library plugin versions up to and including 2.1.4.
CVE-2025-24728 is an SQL Injection vulnerability that allows for blind SQL injection exploitation.
Yes, CVE-2025-24728 can be exploited remotely if the targeted software is accessible over the network.