HIGH
WordPress Zoho Campaigns plugin <= 2.0.6 - SQL Injection vulnerability
Published Mar 28, 2024
8.5
HIGHCVSS 3.1
EPSS 0.52%
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.6.
Affected products
-
Affected
- ≤ 2.0.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Zoho Campaigns | Zoho Campaigns | unaffected | Affected
|
No data.
-
Affected
- ≥ 0, ≤ 2.0.6
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 2.0.7 or a higher version.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Mar 28, 2024
Updated Apr 28, 2026
Reserved Mar 26, 2024
Link CVE-2024-30239
CISA Vulnrichment
Updated Aug 8, 2024
Red Hat
No data
GitHub
No data