Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infotuts SW Contact Form allows Blind SQL Injection.This issue affects SW Contact Form: from n/a through 1.0.
History

Thu, 24 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Infotuts
Infotuts sw Contact Form
CPEs cpe:2.3:a:infotuts:sw_contact_form:*:*:*:*:*:wordpress:*:*
Vendors & Products Infotuts
Infotuts sw Contact Form

Mon, 21 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Oct 2024 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infotuts SW Contact Form allows Blind SQL Injection.This issue affects SW Contact Form: from n/a through 1.0.
Title WordPress SW Contact Form plugin <= 1.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-10-20T10:01:20.580Z

Updated: 2024-10-21T19:18:46.801Z

Reserved: 2024-10-17T09:51:09.447Z

Link: CVE-2024-49612

cve-icon Vulnrichment

Updated: 2024-10-21T19:18:40.593Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-20T10:15:04.053

Modified: 2024-10-24T15:33:14.523

Link: CVE-2024-49612

cve-icon Redhat

No data.