Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Brunlorenz

#45200of 57,352
6.5Total CVSS
Vulnerabilities · 1
PT-2026-97683
6.5
2026-09-24
Forma Lms · Forma Lms · CVE-2026-96777
**Name of the Vulnerable Software and Affected Versions** Forma LMS versions prior to 4.1.44 **Description** A SQL injection issue exists in the Multi-User-Selector AJAX Endpoint. This occurs when the `Name` argument is manipulated within the `UserselectorAdmController::getDataTask()` function, located in the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint. This flaw allows a remote attacker to execute unauthorized database queries. **Recommendations** Update Forma LMS to a version newer than 4.1.43. As a temporary mitigation, restrict access to the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint or avoid using the `Name` argument within the Multi-User-Selector component.