CVE-2024-38773
Formlift
CVE-2024-38773: A critical SQL Injection vulnerability exists in Adrian Tobey FormLift for Infusionsoft Web Forms, affecting versions up to 7.5.17. This flaw allows for Blind SQL Injection, where attackers can infer information about the database without directly seeing the results of their queries. With a SOCRadar Vulnerability Risk Score (SVRS) of 84, this vulnerability is classified as critical and requires immediate attention. An attacker could potentially compromise the entire database, gaining access to sensitive customer data, financial records, or other confidential information. Given its presence "In The Wild" as indicated by security researchers, and the high SVRS, organizations using FormLift should patch immediately to mitigate the significant risk of exploitation. Failing to address this vulnerability could result in severe data breaches and reputational damage.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.