CVE-2024-55988
CRITICALAmol Nirmala Waman Navayan CSV Export <1.0.9 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-55988. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2024-55988, an unauthenticated SQL injection vulnerability in the Navayan CSV Export WordPress plugin. The PoC uses sqlmap to demonstrate the exploitation of the 'nycsv' parameter, confirming the vulnerability and extracting database information.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export navayan-csv-export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through <= 1.0.9.
Exploits (1)
This repository contains a proof-of-concept for CVE-2024-55988, an unauthenticated SQL injection vulnerability in the Navayan CSV Export WordPress plugin. The PoC uses sqlmap to demonstrate the exploitation of the 'nycsv' parameter, confirming the vulnerability and extracting database information.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L