PT-2026-71016 · 10Web · Form Maker
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Form Maker by 10Web versions prior to 1.15.45
Description
This issue occurs when the software fails to properly parameterize a user-controlled value used in a dynamic SQL query for a database-backed choice field. This allows users with subscriber-level privileges to perform a second-order SQL injection, which is a type of attack where malicious input is stored by the application and later executed as a command when the stored data is retrieved and used in a different query. The vulnerable variable is
display name.Recommendations
Update Form Maker by 10Web to version 1.15.45 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Form Maker