HIGH🇬🇧 English

CVE-2022-24985

CVSS 8.8v3.1pub. 2022-02-16upd. 2024-11-21

Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Jqueryform

    APP
    Jqueryform
    < 2022-02-05
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2022-24984CRITICAL9.8PL ✓ten sam produkt

JQueryForm: nieuwierzytelniony upload pliku i RCE przez bypass walidacji

CVE-2022-24983HIGH7.5ten sam produkt

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded f...

CVE-2022-24981MEDIUM6.1ten sam produkt

A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 al...

CVE-2022-24982MEDIUM6.5ten sam produkt

Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the clear...

CVE-2016-9482CRITICAL9.8PL ✓ten sam vendor

Auth Bypass w kodzie generowanym przez PHP FormMail Generator