Forma Lms · Forma Lms · CVE-2026-96777
**Name of the Vulnerable Software and Affected Versions**
Forma LMS versions prior to 4.1.44
**Description**
A SQL injection issue exists in the Multi-User-Selector AJAX Endpoint. This occurs when the `Name` argument is manipulated within the `UserselectorAdmController::getDataTask()` function, located in the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint. This flaw allows a remote attacker to execute unauthorized database queries.
**Recommendations**
Update Forma LMS to a version newer than 4.1.43.
As a temporary mitigation, restrict access to the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint or avoid using the `Name` argument within the Multi-User-Selector component.