What the vulnerability does
01Description
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
Explanation of Vulnerability in Simple Terms
Visitor Traffic Real Time Statistics Pro versions up to 11.17 contain a SQL injection vulnerability accessible over the network without authentication. An attacker can craft malicious input to read sensitive data from the site's database, including user credentials and configuration details. The vulnerability also allows limited disruption of database availability. Update to a version newer than 11.17 immediately.
What an attacker can do
Read sensitive data from the site database, including user credentials and site configuration.
Potential impact on your site
Attackers can steal user passwords, email addresses, and other database contents without logging in.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities