CVE-2024-6723

The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:meowapps:ai_engine:*:*:*:*:*:wordpress:*:*

History

27 Sep 2024, 18:50

Type Values Removed Values Added
First Time Meowapps
Meowapps ai Engine
CWE CWE-89
References () https://wpscan.com/vulnerability/fbd2152e-0aa1-4b56-a6a3-2e6ec78e08a5/ - () https://wpscan.com/vulnerability/fbd2152e-0aa1-4b56-a6a3-2e6ec78e08a5/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:meowapps:ai_engine:*:*:*:*:*:wordpress:*:*

13 Sep 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7

13 Sep 2024, 14:06

Type Values Removed Values Added
Summary
  • (es) El complemento AI Engine para WordPress anterior a la versión 2.4.8 no desinfecta ni escapa correctamente un parámetro antes de usarlo en una declaración SQL, lo que genera una inyección SQL que los usuarios administradores pueden explotar cuando ven las discusiones del chatbot.

13 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-13 06:15

Updated : 2024-09-27 18:50


NVD link : CVE-2024-6723

Mitre link : CVE-2024-6723

CVE.ORG link : CVE-2024-6723


JSON object : View

Products Affected

meowapps

  • ai_engine
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')