Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.
References
Link | Resource |
---|---|
https://JQueryForm.com | Vendor Advisory |
https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560 | Third Party Advisory |
https://www.nou-systems.com/cyber-security | Third Party Advisory |
Configurations
History
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
25 Feb 2022, 14:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:jqueryform:jqueryform:*:*:*:*:*:*:*:* | |
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : 6.0
v3 : 8.8 |
References | (MISC) https://JQueryForm.com - Vendor Advisory | |
References | (MISC) https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560 - Third Party Advisory | |
References | (MISC) https://www.nou-systems.com/cyber-security - Third Party Advisory |
16 Feb 2022, 22:30
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-02-16 22:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-24985
Mitre link : CVE-2022-24985
CVE.ORG link : CVE-2022-24985
JSON object : View
Products Affected
jqueryform
- jqueryform
CWE