What the vulnerability does
01Description
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
Explanation of Vulnerability in Simple Terms
Formidable Forms Signature Online Contract Automation versions up to 2.0.1 contain an authorization bypass vulnerability. An attacker can read sensitive contract and signature data by manipulating user-controlled identifiers without authentication. The vulnerability affects the core contract retrieval mechanism and exposes confidential information to unauthorized parties.
What an attacker can do
Read contract and signature data belonging to other users without logging in.
Potential impact on your site
Confidential contracts and digital signatures may be exposed to unauthorized parties.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities