CVE-2023-2527: Integration for Contact Form 7 and Zoho CRM, Bigin < 1.2.4 - Admin+ SQLi
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Contact Form 7 and Zoho CRM plugin?
The vulnerability ID for the Contact Form 7 and Zoho CRM plugin is CVE-2023-2527.
What is the severity of CVE-2023-2527?
The severity of CVE-2023-2527 is medium with a severity value of 4.8.
What is the affected software for CVE-2023-2527?
The affected software for CVE-2023-2527 is the Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before version 1.2.4.
What is the risk of CVE-2023-2527?
The risk of CVE-2023-2527 is a SQL injection vulnerability that can be exploited by high privilege users such as admin.
How can I fix CVE-2023-2527?
To fix CVE-2023-2527, update the Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin to version 1.2.4 or higher.