Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.3
CVE-2024-22721
- EPSS 0.19%
- Veröffentlicht 11.04.2024 20:15:33
- Zuletzt bearbeitet 08.04.2025 15:20:50
Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.
7.2
CVE-2024-22722
- EPSS 0.89%
- Veröffentlicht 11.04.2024 20:15:33
- Zuletzt bearbeitet 08.04.2025 15:20:57
Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.
6.1
CVE-2024-22637
- EPSS 0.45%
- Veröffentlicht 25.01.2024 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:56:30
Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.