What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1.
Explanation of Vulnerability in Simple Terms
JetFormBuilder versions up to 3.5.6.1 contain a code injection vulnerability that allows authenticated users with low privileges to run arbitrary PHP code on the site. The vulnerability affects the form builder's handling of user input and can impact confidentiality, integrity, and availability of the entire site. Update to version 3.6.3 or later to remediate.
What an attacker can do
Run arbitrary PHP code on the site with the privileges of the web server.
Potential impact on your site
Complete compromise of site data, files, and functionality if an authenticated user with low privileges is compromised or malicious.
Conditions required to exploit
Attacker must have a low-privilege authenticated account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities