CVE-2024-25928

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sitepact:contact_form_7_extension_for_klaviyo:*:*:*:*:*:wordpress:*:*

History

25 Feb 2025, 15:38

Type Values Removed Values Added
First Time Sitepact
Sitepact contact Form 7 Extension For Klaviyo
References () https://patchstack.com/database/vulnerability/sitepact-klaviyo-contact-form-7/wordpress-sitepact-s-contact-form-7-extension-for-klaviyo-plugin-1-0-5-reflected-xss-via-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/sitepact-klaviyo-contact-form-7/wordpress-sitepact-s-contact-form-7-extension-for-klaviyo-plugin-1-0-5-reflected-xss-via-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:sitepact:contact_form_7_extension_for_klaviyo:*:*:*:*:*:wordpress:*:*

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/sitepact-klaviyo-contact-form-7/wordpress-sitepact-s-contact-form-7-extension-for-klaviyo-plugin-1-0-5-reflected-xss-via-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/sitepact-klaviyo-contact-form-7/wordpress-sitepact-s-contact-form-7-extension-for-klaviyo-plugin-1-0-5-reflected-xss-via-sql-injection-vulnerability?_s_id=cve -

08 Jul 2024, 10:15

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.

23 Feb 2024, 16:14

Type Values Removed Values Added
Summary
  • (es) Neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ('inyección SQL') en Sitepact. Este problema afecta a Sitepact: desde n/a hasta 1.0.5.

23 Feb 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-23 12:15

Updated : 2025-02-25 15:38


NVD link : CVE-2024-25928

Mitre link : CVE-2024-25928

CVE.ORG link : CVE-2024-25928


JSON object : View

Products Affected

sitepact

  • contact_form_7_extension_for_klaviyo
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')