First published: Thu Apr 11 2024(Updated: )
Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22722 is a high-severity vulnerability due to its potential for remote command execution.
To fix CVE-2024-22722, update Form Tools to the latest version that addresses this vulnerability.
CVE-2024-22722 is classified as a Server Side Template Injection (SSTI) vulnerability.
CVE-2024-22722 affects users of Form Tools version 3.1.1.
Attackers can exploit CVE-2024-22722 by injecting arbitrary commands through the Group Name field in the add forms section.