CVE-2024-52436SQL Injection in Iqbal Post Smtp

CWE-89SQL Injection3 documents3 sources
Severity
7.2HIGHNVD
EPSS
0.4%
top 39.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a through <= 2.9.9.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

CVEListV5saad_iqbal/post_smtp2.9.9

🔴Vulnerability Details

2
GHSA
GHSA-c9gx-rq5w-8v24: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Post SMTP allows Blind SQL Injection2024-11-18
CVEList
WordPress Post SMTP plugin <= 2.9.9 - SQL Injection vulnerability2024-11-18
CVE-2024-52436 — SQL Injection in Saad Iqbal Post Smtp | cvebase