First published: Thu Apr 11 2024(Updated: )
SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22719 is categorized as a medium severity SQL Injection vulnerability.
To fix CVE-2024-22719, it is recommended to upgrade to the latest version of Form Tools that addresses this vulnerability.
CVE-2024-22719 affects Form Tools version 3.1.1, allowing SQL injection through the 'keyword' parameter.
CVE-2024-22719 allows attackers to execute arbitrary SQL commands by exploiting a vulnerability in search functionality.
Exploiting CVE-2024-22719 can lead to unauthorized data access, data manipulation, and potentially complete compromise of the affected database.