What the vulnerability does
01Description
Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.
Explanation of Vulnerability in Simple Terms
Form Maker by 10Web versions up to 1.15.44 contain a SQL injection vulnerability in database queries. An authenticated user with low privileges can craft malicious input to extract sensitive data from the site's database, including user information and configuration details. The vulnerability affects multiple database operations and can impact site availability.
What an attacker can do
Extract sensitive data from the site database, including user records and site configuration.
Potential impact on your site
Unauthorized access to database contents, potential exposure of user data and site secrets, possible service disruption.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities