CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-38773

Critical Severity
Formlift
SVRS
84/100

CVSSv3
9.8/10

EPSS
0.002/1

CVE-2024-38773: A critical SQL Injection vulnerability exists in Adrian Tobey FormLift for Infusionsoft Web Forms, affecting versions up to 7.5.17. This flaw allows for Blind SQL Injection, where attackers can infer information about the database without directly seeing the results of their queries. With a SOCRadar Vulnerability Risk Score (SVRS) of 84, this vulnerability is classified as critical and requires immediate attention. An attacker could potentially compromise the entire database, gaining access to sensitive customer data, financial records, or other confidential information. Given its presence "In The Wild" as indicated by security researchers, and the high SVRS, organizations using FormLift should patch immediately to mitigate the significant risk of exploitation. Failing to address this vulnerability could result in severe data breaches and reputational damage.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:H
I:H
A:H
2024-07-22

2024-07-29

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-38773 | Adrian Tobey FormLift for Infusionsoft Web Forms Plugin up to 7.5.17 on WordPress sql injection
vuldb.com2024-07-22
CVE-2024-38773 | Adrian Tobey FormLift for Infusionsoft Web Forms Plugin up to 7.5.17 on WordPress sql injection | A vulnerability was found in Adrian Tobey FormLift for Infusionsoft Web Forms Plugin up to 7.5.17 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to sql injection. This vulnerability was named CVE-2024-38773. The attack can be initiated remotely. There is no exploit
cve-2024-38773
domains
urls
cves

Social Media

CVE-2024-38773 (CVSS:9.3, CRITICAL) is Undergoing Analysis. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormL..https://t.co/c02f1azZYz #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppFormliftformlift_for_infusionsoft_web_forms

References

ReferenceLink
[email protected]https://patchstack.com/database/vulnerability/formlift/wordpress-formlift-plugin-7-5-17-unauthenticated-blind-sql-injection-vulnerability?_s_id=cve

CWE Details

CWE IDCWE NameDescription
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence