Vulnerability Description
Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or manipulate database information by sending crafted payloads to the collections page.
Related Weaknesses (CWE)
References
- https://elements.envato.com/xhibiter-nft-marketplace-html-template-AQN45FA
- https://www.exploit-db.com/exploits/52060
- https://www.vulncheck.com/advisories/xhibiter-nft-marketplace-sql-injection-via-
FAQ
What is CVE-2024-58290?
CVE-2024-58290 is a documented vulnerability. Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploi...
How severe is CVE-2024-58290?
CVSS scoring is not yet available for CVE-2024-58290. Check NVD for updates.
Is there a patch for CVE-2024-58290?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.