Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability in Contact Form to Any API
CVE-2024-30242
What is CVE-2024-30242?
An SQL Injection vulnerability exists in IT Path Solutions' Contact Form to Any API plugin that potentially allows unauthorized access to database contents through improper handling of user input. Specifically, this issue can be exploited when the plugin processes input fields that fail to adequately sanitize special characters used within SQL commands. By exploiting this flaw, attackers could manipulate SQL queries to retrieve or alter sensitive data stored within the database. It is crucial for users of the Contact Form to Any API plugin versions from n/a to 1.1.8 to assess their exposure and implement appropriate security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Form to Any API <= 1.1.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved