CVE-2026-96777: Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection
A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTask of the file /appCore/ajax.admserver.php?r=adm/userselector/getData of the component Multi-User-Selector AJAX Endpoint. This manipulation of the argument Name causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be initiated remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which deployments are affected?
Forma LMS versions up to 4.1.43 are affected. The issue is in the Multi-User-Selector AJAX endpoint at /appCore/ajax.adm_server.php?r=adm/userselector/getData.
What input is vulnerable?
The SQL injection is caused by manipulation of the Name argument handled by UserselectorAdmController::getDataTask.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.