vendor:
Form Maker
by:
SunCSR (Sun* Cyber Security Research)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Form Maker
Affected Version From: <= 5.4.1
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:10web:form_maker
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2020
WordPress Plugin Form Maker 5.4.1 – ‘s’ SQL Injection (Authenticated)
SQL injection in the Form Maker by 10Web WordPress Plugin before 5.4.1 exists via the /wordpress/wp-admin/admin.php?page=blocked_ips_fm&s=1" s parameter.
Mitigation:
Upgrade to the latest version of the Form Maker by 10Web WordPress Plugin.