Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.
References
Link | Resource |
---|---|
https://JQueryForm.com | Vendor Advisory |
https://www.nou-systems.com/cyber-security | Third Party Advisory |
https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560 | Third Party Advisory |
Configurations
Information
Published : 2022-02-16 14:15
Updated : 2022-02-25 06:24
NVD link : CVE-2022-24985
Mitre link : CVE-2022-24985
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
jqueryform
- jqueryform