SQL Injection Vulnerability in Zoho CRM Lead Magnet
CVE-2024-49297

8.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
17 October 2024

Summary

A vulnerability exists in the Zoho CRM Lead Magnet that allows for SQL Injection due to improper neutralization of special elements utilized in SQL commands. This issue compromises data security by enabling attackers to manipulate SQL queries and potentially gain unauthorized access to sensitive information. Affected versions include those prior to 1.7.9.0. Organizations using this plugin should implement immediate security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Zoho CRM Lead Magnet <= 1.7.9.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc / truonghuuphuc (Patchstack Alliance)
.