What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
Explanation of Vulnerability in Simple Terms
Ninja Forms versions up to 3.8.4 contain a code injection vulnerability that allows authenticated users with low privileges to inject and execute arbitrary code. An attacker can read or modify sensitive data on the site by crafting malicious input. The vulnerability requires an authenticated account but no user interaction from the victim.
What an attacker can do
Inject and run arbitrary code to read or modify site data.
Potential impact on your site
Any registered user can inject code to access or alter form data and site content.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities