Vulnerabilities > Crmperks > Integration FOR Contact Form 7 AND Zoho CRM Bigin > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-06-19 CVE-2023-2527 Cross-site Scripting vulnerability in Crmperks Integration for Contact Form 7 and Zoho Crm, Bigin 1.2.2
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
network
low complexity
crmperks CWE-79
4.8