CVE-2024-38773
WordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability
Vexday Risk Score
43Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.3EPSS 2.0%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
22 Jul 2024Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.17.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Affected products
Adrian Tobey · FormLift for Infusionsoft Web FormsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →