PT-2026-97683 · Forma Lms · Forma Lms
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Forma LMS versions prior to 4.1.44
Description
A SQL injection issue exists in the Multi-User-Selector AJAX Endpoint. This occurs when the
Name argument is manipulated within the UserselectorAdmController::getDataTask() function, located in the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint. This flaw allows a remote attacker to execute unauthorized database queries.Recommendations
Update Forma LMS to a version newer than 4.1.43.
As a temporary mitigation, restrict access to the '/appCore/ajax.adm server.php?r=adm/userselector/getData' endpoint or avoid using the
Name argument within the Multi-User-Selector component.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Forma Lms