HIGH🇵🇱 Wersja polska

CVE-2022-24985

CVSS 8.8v3.1pub. 2022-02-16upd. 2024-11-21

Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Jqueryform

    APP
    Jqueryform
    < 2022-02-05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-24984CRITICAL9.8PL ✓same product

JQueryForm: nieuwierzytelniony upload pliku i RCE przez bypass walidacji

CVE-2022-24983HIGH7.5same product

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded f...

CVE-2022-24981MEDIUM6.1same product

A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 al...

CVE-2022-24982MEDIUM6.5same product

Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the clear...

CVE-2016-9482CRITICAL9.8PL ✓same vendor

Auth Bypass w kodzie generowanym przez PHP FormMail Generator