CVE-2023-50838
HIGH WAF: High
CVSS 7.2
Published: 2023-12-28
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Contact forms and much more: from n/a through 8.5.5.
WAF Coverage Analysis
SQL Injection
High WAF Coverage
OWASP: A03:2021 Injection
942xxx - SQL Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| basixonline | nex-forms | up to 8.5.5 |
References
- patchstack.com (Third Party Advisory)