CVE-2024-6937

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Jul 21, 2024
Updated: Jul 22, 2024
CWE ID 73

Summary

CVE-2024-6937 is a vulnerability found in formtools.org Form Tools 3.1.1. The vulnerability affects the function curl_exec of the file /admin/forms/option_lists/edit.php of the component Import Option List. It allows for remote file inclusion, enabling attackers to manipulate the URL argument and launch attacks remotely. The exploit has been made public and poses a potential danger to organizations using this software. The vendor has been notified but has not responded. Remediation measures should be taken immediately to address this vulnerability and protect against potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share