CVE Published: 08/06/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: Patchstack |
Vendor: BestWebSoft |
Product: Contact Form to DB by BestWebSoft Status : PUBLISHED
CVE-2024-35678 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.This issue affects Contact Form to DB by BestWebSoft: from n/a through 1.7.2.
Metrics
CVSS Version: 3.1 |
Base Score: 8.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L