VDB
CVE-2024-51882
CVE-2024-51882
PUBLISHED
CVSS 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ehues Gboy Custom Google Map allows Blind SQL Injection.This issue affects Gboy Custom Google Map: from n/a through 1.2.
EPSS 0.42% · 36.1th percentile
Risk Scores
CVSS 3.1
8.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
EPSS Score
0.42%
36.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ehues | gboy_custom_google_map | 0, 0 |
| Ehues | Gboy Custom Google Map | n/a |
| gopalkumar315 | Gboy Custom Google Map | 0 |
Timeline
- Nov 11, 2024 Coalition ESS Score
- Nov 11, 2024 CVE Published
- Nov 11, 2024 PoC Published
- Nov 11, 2024 PoC Published
- Nov 12, 2024 EPSS Score
- Nov 12, 2024 Coalition ESS Score
- Nov 15, 2024 Coalition ESS Score
- Nov 30, 2024 EPSS Score
- Dec 19, 2024 EPSS Score
- Jan 6, 2025 EPSS Score
- Feb 11, 2025 EPSS Score
- Mar 1, 2025 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-51882 advisory
- https://patchstack.com/database/Wordpress/Plugin/gboy-custom-google-map/vulnerability/wordpress-gboy-custom-google-map-plugin-1-2-sql-injection-vulnerability?_s_id=cve url
- https://patchstack.com/database/vulnerability/gboy-custom-google-map/wordpress-gboy-custom-google-map-plugin-1-2-sql-injection-vulnerability?_s_id=cve url