CVE-2024-49297: WordPress Zoho CRM Lead Magnet plugin <= 1.7.9.7 - SQL Injection vulnerability
Published Oct 17, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.7.9.7.
Affected Software
1 affected component
Zoho Zoho CRM Lead Magnet<=1.7.9.7
Event History
Oct 17, 2024
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-49297?
CVE-2024-49297 has a high severity rating due to its potential for SQL Injection attacks affecting Zoho CRM Lead Magnet.
2
How do I fix CVE-2024-49297?
To fix CVE-2024-49297, update Zoho CRM Lead Magnet to version 1.7.9.1 or later.
3
Which versions of Zoho CRM Lead Magnet are affected by CVE-2024-49297?
CVE-2024-49297 affects Zoho CRM Lead Magnet versions up to and including 1.7.9.0.
4
Can CVE-2024-49297 impact WordPress installations?
Yes, CVE-2024-49297 can impact the WordPress Zoho CRM Lead Magnet plugin up to version 1.7.9.0.
5
Is CVE-2024-49297 an SQL Injection vulnerability?
Yes, CVE-2024-49297 is classified as an SQL Injection vulnerability affecting Zoho CRM Lead Magnet.