Beware: Smart Manager 8.27.0’s SQL Injection Surprise! (CVE-2024-0566)
Heads up, Smart Manager 8.27.0 users! The plugin’s so eager to sort your life out, it forgot to sanitize its SQL inputs. This oversight allows admins to indulge in a time-based SQL injection vulnerability. So, update now or risk your server taking a 20-second nap!

Hot Take:
Who knew managing a store’s inventory could be as risky as juggling chainsaws? The latest Smart Manager update might just have you rethinking your life choices—especially if you’re an admin with a penchant for SQL adventures!
Key Points:
- Smart Manager 8.27.0 is susceptible to an SQL injection vulnerability.
- The flaw resides in the admin AJAX endpoint with improper parameter sanitization.
- High-privilege users, like admins, can exploit this to inject SQL commands.
- The vulnerability affects sorting parameters within AJAX requests.
- Users are urged to update the plugin and secure the vulnerable endpoint.
Already a member? Log in here