{"api_version":"1","generated_at":"2026-07-23T10:08:33+00:00","cve":"CVE-2022-24985","urls":{"html":"https://cve.report/CVE-2022-24985","api":"https://cve.report/api/cve/CVE-2022-24985.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-24985","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-24985"},"summary":{"title":"CVE-2022-24985","description":"Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-02-16 22:15:00","updated_at":"2023-08-08 14:21:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://www.nou-systems.com/cyber-security","name":"https://www.nou-systems.com/cyber-security","refsource":"MISC","tags":["Third Party Advisory"],"title":"Cybersecurity — nou Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://JQueryForm.com","name":"https://JQueryForm.com","refsource":"MISC","tags":["Vendor Advisory"],"title":"The Right Form Builder- Building Web Forms in Just the Way You Like It, Without Subscription!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560","name":"https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560","refsource":"MISC","tags":["Third Party Advisory"],"title":"gist:4d0a1ede76d4e97083b3435f820bf560 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-24985","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24985","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"24985","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jqueryform","cpe5":"jqueryform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-24985","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://JQueryForm.com","refsource":"MISC","name":"https://JQueryForm.com"},{"url":"https://www.nou-systems.com/cyber-security","refsource":"MISC","name":"https://www.nou-systems.com/cyber-security"},{"refsource":"MISC","name":"https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560","url":"https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560"}]}},"nvd":{"publishedDate":"2022-02-16 22:15:00","lastModifiedDate":"2023-08-08 14:21:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6},"severity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jqueryform:jqueryform:*:*:*:*:*:*:*:*","versionEndExcluding":"2022-02-05","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"24985","Ordinal":"228423","Title":"CVE-2022-24985","CVE":"CVE-2022-24985","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"24985","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}