CVE Published: 22/07/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: Patchstack |
Vendor: Adrian Tobey |
Product: FormLift for Infusionsoft Web Forms Status : PUBLISHED
CVE-2024-38773 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.17.
Metrics
CVSS Version: 3.1 |
Base Score: 9.3 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L