CVE Published: 17/10/2024 |
CVE Updated: 17/10/2024 |
CVE Year: 2024 Source: Patchstack |
Vendor: cmssoft |
Product: CSV Product Import Export for WooCommerce Status : PUBLISHED
CVE-2024-49244 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in cmssoft CSV Product Import Export for WooCommerce allows SQL Injection.This issue affects CSV Product Import Export for WooCommerce: from n/a through 1.0.0.
Metrics
CVSS Version: 3.1 |
Base Score: 8.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L