What the vulnerability does
01Description
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
Explanation of Vulnerability in Simple Terms
Forminator versions up to 1.57.1 contain an authentication bypass vulnerability that allows attackers to replay captured authentication tokens to gain unauthorized access. The vulnerability requires network access but no user interaction or elevated privileges. An attacker can intercept and reuse valid authentication credentials to perform unauthorized actions on the site.
What an attacker can do
Replay captured authentication tokens to bypass login and perform unauthorized actions on the site.
Potential impact on your site
Unauthorized users can gain access to Forminator functionality and potentially modify forms or access submitted data without valid credentials.
Conditions required to exploit
Attacker must be able to capture valid authentication tokens (e.g., via network sniffing or man-in-the-middle attack).
Key dates
External resources
Related vulnerabilities