Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-8379
HistorySep 30, 2024 - 6:00 a.m.

CVE-2024-8379 Cost Calculator Builder < 3.2.29 - Admin+ SQL Injection

2024-09-3006:00:07
WPScan
github.com
cve-2024-8379
cost calculator builder
wordpress
sql injection
admin

AI Score

7.5

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:stylemixthemes:cost_calculator_builder:*:*:*:*:*:*:*:*"
    ],
    "vendor": "stylemixthemes",
    "product": "cost_calculator_builder",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "3.2.29",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

7.5

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-8379