PT-2024-37975 · Unknown · Form Tools
Dee.Mirage
·
Published
2024-07-21
·
Updated
2024-10-01
·
CVE-2024-6937
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Form Tools version 3.1.1
Description
A problematic issue was found in the Import Option List component, specifically affecting the
curl exec function in the /admin/forms/option lists/edit.php file. The manipulation of the url argument leads to file inclusion, and it is possible to launch the attack remotely. The issue has been publicly disclosed and may be exploited. The vendor was contacted about this disclosure but did not respond.Recommendations
For version 3.1.1, consider disabling the
curl exec function in the /admin/forms/option lists/edit.php file as a temporary workaround until a patch is available. Restrict access to the Import Option List component to minimize the risk of exploitation. Avoid using the url argument in the affected function until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Form Tools