Machform

Machform

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 10.12%
  • Veröffentlicht 01.07.2024 22:15:03
  • Zuletzt bearbeitet 30.04.2025 16:38:05

MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.

Exploit
  • EPSS 7.14%
  • Veröffentlicht 01.07.2024 22:15:03
  • Zuletzt bearbeitet 30.04.2025 16:38:17

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

Exploit
  • EPSS 11.06%
  • Veröffentlicht 01.07.2024 22:15:03
  • Zuletzt bearbeitet 30.04.2025 16:38:29

Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

Exploit
  • EPSS 28.05%
  • Veröffentlicht 01.07.2024 22:15:02
  • Zuletzt bearbeitet 30.04.2025 16:37:36

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

  • EPSS 0.24%
  • Veröffentlicht 29.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:45:55

Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to receive malformed content.

  • EPSS 0.15%
  • Veröffentlicht 29.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:45:55

Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.

  • EPSS 0.24%
  • Veröffentlicht 29.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:45:55

Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with forms through upload.php.

  • EPSS 1.29%
  • Veröffentlicht 29.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:45:55

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

  • EPSS 0.22%
  • Veröffentlicht 29.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:45:55

Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

Exploit
  • EPSS 12.67%
  • Veröffentlicht 26.05.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:39

An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerabilit...