CVE-2024-35678

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.This issue affects Contact Form to DB by BestWebSoft: from n/a through 1.7.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bestwebsoft:contact_form_to_db:*:*:*:*:*:wordpress:*:*

History

26 Nov 2024, 16:04

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/contact-form-to-db/wordpress-contact-form-to-db-by-bestwebsoft-plugin-1-7-2-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/contact-form-to-db/wordpress-contact-form-to-db-by-bestwebsoft-plugin-1-7-2-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
First Time Bestwebsoft
Bestwebsoft contact Form To Db
CPE cpe:2.3:a:bestwebsoft:contact_form_to_db:*:*:*:*:*:wordpress:*:*

21 Nov 2024, 09:20

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/contact-form-to-db/wordpress-contact-form-to-db-by-bestwebsoft-plugin-1-7-2-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/contact-form-to-db/wordpress-contact-form-to-db-by-bestwebsoft-plugin-1-7-2-sql-injection-vulnerability?_s_id=cve -
Summary
  • (es) Neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ("Inyección SQL") en BestWebSoft Contact Form to DB de BestWebSoft. Este problema afecta el Contact Form to DB de BestWebSoft: desde n/a hasta 1.7.2.

08 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-08 16:15

Updated : 2024-11-26 16:04


NVD link : CVE-2024-35678

Mitre link : CVE-2024-35678

CVE.ORG link : CVE-2024-35678


JSON object : View

Products Affected

bestwebsoft

  • contact_form_to_db
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')