CVE-2019-10866
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
- Affected products
- Form Maker
- 10web Form Maker
- < 1.13.3
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 6.2% (93th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2019-05-23
CVE-2019-10866 at NVD
5 known exploits for CVE-2019-10866
Proof-of-concept code and exploit modules indexed by Sploitus