SQL Injection Vulnerability in Zoho CRM Lead Magnet
CVE-2024-49297
8.5HIGH
Summary
A vulnerability exists in the Zoho CRM Lead Magnet that allows for SQL Injection due to improper neutralization of special elements utilized in SQL commands. This issue compromises data security by enabling attackers to manipulate SQL queries and potentially gain unauthorized access to sensitive information. Affected versions include those prior to 1.7.9.0. Organizations using this plugin should implement immediate security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Zoho CRM Lead Magnet <= 1.7.9.0
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc / truonghuuphuc (Patchstack Alliance)