CVE-2023-48433
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 20, 2023
Updated: Dec 22, 2023
CWE ID 89
Summary
CVE-2023-35915 is an SQL Injection vulnerability affecting WooPayments – Fully Integrated Solution Built and Supported by Woo. The issue allows malicious actors to inject malicious SQL code into the application, potentially leading to unauthorized access, data theft, or data modification. This vulnerability exists in WooPayments versions from n/a through 5.9.0, putting numerous installations at risk. It is important that users upgrade to a patched version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share