NA

CVE-2024-30491

Published: 29/03/2024 Updated: 01/04/2024

Vulnerability Summary

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a up to and including 5.7.8.

Github Repositories

CVE-2024-30491-Poc ProfileGrid <= 578 - Authenticated (Subscriber+) SQL Injection wwwwordfencecom/threat-intel/vulnerabilities/wordpress-plugins/profilegrid-user-profiles-groups-and-communities/profilegrid-578-authenticated-subscriber-sql-injection Build wordpress: docker-compose -f stackyml up Step 1: Diff ProfileGrid 578 and ProfileGrid 579 File: incl