CVE-2022-24984
- EPSS 2.43%
- Veröffentlicht 16.02.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:30
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the cli...
CVE-2022-24985
- EPSS 0.7%
- Veröffentlicht 16.02.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:30
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts m...
CVE-2022-24981
- EPSS 0.45%
- Veröffentlicht 16.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:30
A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to admin.php.
CVE-2022-24982
- EPSS 0.26%
- Veröffentlicht 16.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:30
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form users. admin.php contains a hidden base64-encoded string with these credentials.
CVE-2022-24983
- EPSS 2.18%
- Veröffentlicht 16.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:30
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underl...