CVE Published: 11/10/2024 |
CVE Updated: 11/10/2024 |
CVE Year: 2024 Source: Patchstack |
Vendor: NinjaTeam |
Product: Multi Step for Contact Form Status : PUBLISHED
CVE-2024-47331 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in NinjaTeam Multi Step for Contact Form allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through 2.7.7.
Metrics
CVSS Version: 3.1 |
Base Score: 9.3 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L