CVE-2024-47331
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 11, 2024
Updated: Nov 14, 2024
CWE ID 89
Summary
CVE-2024-47331 is a newly disclosed SQL Injection vulnerability affecting NinjaTeam Multi Step for Contact Form. The flaw, which allows malicious SQL commands to be executed, can impact versions 2.7.7 and below. An attacker can exploit this weakness by injecting malicious SQL statements into input fields designed for user input. Successful exploitation could lead to unauthorized access to sensitive data or even system takeover. Users of the affected software are advised to apply the latest patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.