What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.17.
Explanation of Vulnerability in Simple Terms
02Summary
FormLift for Infusionsoft Web Forms versions 7.5.17 and earlier contain a SQL injection vulnerability that allows unauthenticated attackers to read sensitive data from the database without user interaction. The vulnerability affects the web form processing logic and can also cause partial service disruption. No authentication or special privileges are required to exploit this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site's database, including user information and configuration details.
Potential impact on your site
04Site Impact
Attackers can extract database contents without logging in, potentially exposing user data and site configuration.
Conditions required to exploit
05Prerequisites
Network access to the affected FormLift form; no authentication or user interaction required.
Key dates
06Disclosure timeline
July 22, 2024
CVE published
April 28, 2026
Record updated