CVE-2022-24985
Summary
| CVE | CVE-2022-24985 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-16 22:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jqueryform | Jqueryform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cybersecurity — nou Systems | MISC | www.nou-systems.com | Third Party Advisory |
| The Right Form Builder- Building Web Forms in Just the Way You Like It, Without Subscription! | MISC | JQueryForm.com | Vendor Advisory |
| gist:4d0a1ede76d4e97083b3435f820bf560 · GitHub | MISC | gist.github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.