CVE-2024-6934
Formtools
CVE-2024-6934: Cross-site scripting vulnerability found in Form Tools 3.1.1. Attackers can exploit this to inject malicious scripts into the Form URL parameter, affecting users who interact with the compromised page. The vulnerability is present in the /admin/forms/add/step2.php file. Although the CVSS score is 4.8, indicating medium severity, this XSS flaw allows for remote exploitation. The exploit is publicly known and actively used, which increases the risk. Despite attempts to notify the vendor, no response was received, leaving users vulnerable. SOCRadar’s Vulnerability Risk Score (SVRS) is 44, reflecting the public exploit availability despite the moderate CVSS. This highlights the potential for attackers to hijack user sessions or deface web pages.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.