ZeroHour

CVE-2021-24889

PoC
CVSS 3.1
7.2 high
EPSS
1%p68
Published
()
Modified
Description

The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

Vendors
ninjaforms
Products
ninja forms
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.