CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-6936

Medium Severity
Formtools
SVRS
38/100

CVSSv3
4.9/10

EPSS
0.00078/1

CVE-2024-6936 is a code injection vulnerability in formtools.org Form Tools 3.1.1 that allows remote attackers to execute arbitrary code. This vulnerability affects the Setting Handler component via the /admin/settings/index.php?page=accounts file by manipulating the Page Theme argument. The exploit is publicly available, meaning attackers can easily leverage it. Although the CVSS score is 4.9, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 38, reflecting a relatively low immediate risk based on current threat intelligence. However, the existence of a public exploit makes this CVE significant, as it lowers the barrier to entry for attackers. If the SVRS increases over time, immediate patching would be required. This vulnerability poses a risk of unauthorized access and control over the affected Form Tools application.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:H
UI:N
S:U
C:N
I:H
A:N
2024-07-21

2024-10-01

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-6936 | formtools.org Form Tools 3.1.1 Setting index.php Page Theme code injection
vuldb.com2024-07-20
CVE-2024-6936 | formtools.org Form Tools 3.1.1 Setting index.php Page Theme code injection | A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/settings/index.php?page=accounts of the component Setting Handler. The manipulation of the argument Page Theme leads to code injection. The identification of this vulnerability is
vuldb.com
rss
forum
news

Social Media

CVE-2024-6936 A vulnerability, which was classified as problematic, has been found in https://t.co/r9XG75Rof3 Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/se… https://t.co/8yAsKKk9Cl
0
0
1

Affected Software

Configuration 1
TypeVendorProduct
AppFormtoolsform_tools

References

ReferenceLink
[email protected]https://github.com/DeepMountains/Mirage/blob/main/CVE2-2.md
[email protected]https://vuldb.com/?ctiid.271991
[email protected]https://vuldb.com/?id.271991
[email protected]https://vuldb.com/?submit.372318

CWE Details

CWE IDCWE NameDescription
CWE-94Improper Control of Generation of Code ('Code Injection')The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence