Formtools

Form Tools

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 21.07.2024 04:15:02
  • Zuletzt bearbeitet 21.11.2024 09:50:35

A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/settings/index.php?page=accounts of the component Setting Handler. The manipulation ...

  • EPSS 0.13%
  • Veröffentlicht 21.07.2024 04:15:02
  • Zuletzt bearbeitet 21.11.2024 09:50:35

A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.php of the component Import Option List. The manipulation of the argument...

  • EPSS 0.1%
  • Veröffentlicht 21.07.2024 03:15:02
  • Zuletzt bearbeitet 21.11.2024 09:50:35

A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknown code of the file /admin/clients/ of the component User Settings Page. The manipulation leads to cross site scripting. The attack...

  • EPSS 0.05%
  • Veröffentlicht 21.07.2024 02:15:02
  • Zuletzt bearbeitet 21.11.2024 09:50:34

A vulnerability classified as problematic has been found in formtools.org Form Tools 3.1.1. This affects an unknown part of the file /admin/forms/add/step2.php?submission_type=direct. The manipulation of the argument Form URL leads to cross site scri...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 11.04.2024 20:15:33
  • Zuletzt bearbeitet 08.04.2025 15:20:24

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 11.04.2024 20:15:33
  • Zuletzt bearbeitet 08.04.2025 15:20:32

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 11.04.2024 20:15:33
  • Zuletzt bearbeitet 08.04.2025 15:20:41

SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 11.04.2024 20:15:33
  • Zuletzt bearbeitet 08.04.2025 15:20:50

Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 11.04.2024 20:15:33
  • Zuletzt bearbeitet 08.04.2025 15:20:57

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 25.01.2024 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:56:30

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.