momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2024-30502: WP Travel Engine <= 5.7.9 - SQL Injection

CVE: CVE-2024-30502
CNVD: 暂无
CNNVD: 暂无
漏洞类型: SQL注入
漏洞等级: 严重
年份: 2026
POC_ID: 暂无
漏洞描述
WP Travel Engine 5.7.9 and earlier contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL queries, exploit requires user interaction. [已公开] id: CVE-2024-30502 info: name: WP Travel Engine <= 5.7.9 - SQL Injection author: Shivam Kamboj severity: critical description: | WP Travel Engine 5.7.9 and earlier contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL queries, exploit requires user interaction. impact: | Attackers can execute arbitrary SQL queries, potentially leading to data theft, modification, or deletion. remediation: | Update to the latest version of WP Travel Engine. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel-engine/wp-travel-engine-579-unauthenticated-sql-injection - https://patchstack.com/database/wordpress/plugin/wp-travel-engine/vulnerability/wordpress-wp-travel-engine-plugin-5-7-9-unauth-blind-sql-injection-vulnerability - https://plugins.trac.wordpress.org/changeset?old_path=/wp-travel-engine/tags/5.7.9&new_path=/wp-travel-engine/tags/5.8.0
FOFA 语句
暂无
影响范围
WP Travel Engine
漏洞详情
POC: 已公开
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无