PT-2026-97683 · Forma Lms · Forma Lms

·

CVE-2026-96777

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Forma LMS versions prior to 4.1.44
Description A SQL injection issue exists in the Multi-User-Selector AJAX Endpoint. This occurs when the Name argument is manipulated within the UserselectorAdmController::getDataTask() function, located in the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint. This flaw allows a remote attacker to execute unauthorized database queries.
Recommendations Update Forma LMS to a version newer than 4.1.43. As a temporary mitigation, restrict access to the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint or avoid using the Name argument within the Multi-User-Selector component.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96777

Affected Products

Forma Lms