What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.
Explanation of Vulnerability in Simple Terms
02Summary
Form Maker by 10Web versions up to 1.15.20 contain a flaw that allows attackers to modify form data without authentication. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 1.15.20 to prevent unauthorized form manipulation.
What an attacker can do
03Attacker Capabilities
Modify form submissions or data without logging in.
Potential impact on your site
04Site Impact
Form data integrity compromised; attackers can alter submissions without detection.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
June 4, 2024
CVE published
April 28, 2026
Record updated