Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

+1 -800-456-478-23

CVE

CVE-2024-47331 – Multi Step for Contact Form

Published : 2024-10-11

Title: WordPress Multi Step for Contact Form plugin <= 2.7.7 – Unauthenticated SQL Injection vulnerability

Description

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in NinjaTeam Multi Step for Contact Form allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through 2.7.7.

CWE

CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)

CVSS

ScoreSeverityVersionVector String
9.3CRITICAL3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Vendor : n/a

Product: Multi Step for Contact Form

Vulnerable Versions: n/a through 2.7.7

Proof of Concept:

REDACTED

Vulnerability found by: DFEND Security Researcher

References:

https://patchstack.com/database/vulnerability/cf7-multi-step/wordpress-multi-step-for-contact-form-plugin-2-7-7-unauthenticated-sql-injection-vulnerability?_s_id=cve