CVE Published: 09/10/2024 |
CVE Updated: 09/10/2024 |
CVE Year: 2024 Source: Patchstack |
Vendor: Zoho Flow |
Product: Zoho Flow for WordPress Status : PUBLISHED
CVE-2024-47334 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Zoho Flow Zoho Flow for WordPress allows SQL Injection.This issue affects Zoho Flow for WordPress: from n/a through 2.7.1.
Metrics
CVSS Version: 3.1 |
Base Score: 7.6 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L