Awaiting Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Products
Music Store - WordPress eCommerce
- before 1.1.14
Source
vultures@jpcert.or.jp
Tags
CVE-2024-36082 details
Published : June 7, 2024, 4:15 a.m.
Last Modified : June 7, 2024, 2:56 p.m.
Last Modified : June 7, 2024, 2:56 p.m.
Description
SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary SQL commands. Information stored in the database may be obtained or altered by the attacker.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
https://jvn.jp/en/jp/JVN79213252/ | vultures@jpcert.or.jp |
https://plugins.trac.wordpress.org/changeset?new=3085975%40music-store%2Ftrunk%2Fmusic-store.php&old=3079647%40music-store%2Ftrunk%2Fmusic-store.php | vultures@jpcert.or.jp |
https://wordpress.org/plugins/music-store/ | vultures@jpcert.or.jp |
This website uses the NVD API, but is not approved or certified by it.