Sploitus

CVE-2019-10866

5 known exploits for CVE-2019-10866

In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.

Affected products
Form Maker
10web Form Maker
< 1.13.3
Fix
Available
CVSS 3.0
9.8 CRITICAL
EPSS
6.2% (93th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2019-05-23
CVE-2019-10866 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2019-10866

Proof-of-concept code and exploit modules indexed by Sploitus