vendor:
MachForm
by:
Amine Taouirsa
9.8
CVSS
CRITICAL
SQL Injection and Path Traversal
89
CWE
Product Name: MachForm
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2018-6410
CPE: a:appnitro:machform
Metasploit:
N/A
Platforms Tested: Unknown
2018
MachForm SQL Injection and Path Traversal
The form creation platform MachForm from Appnitro is subject to SQL injections that lead to path traversal and arbitrary file upload. The application is widely deployed and with some google dorks it’s possible to find various webpages storing sensitive data as credit card numbers with corresponding security codes. Also, the arbitrary file upload can let an attacker get control of the server by uploading a WebShell.
Mitigation:
The vendor has released a patch to fix the vulnerability.