Lucene search

K
cvePatchstackCVE-2024-32706
HistoryApr 24, 2024 - 9:15 a.m.

CVE-2024-32706

2024-04-2409:15:06
CWE-89
Patchstack
web.nvd.nist.gov
25
cve-2024-32706
improper neutralization
special elements
sql command
arforms

CVSS3

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

9.0%

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Repute info systems ARForms.This issue affects ARForms: from n/a through 6.4.

Affected configurations

Vulners
Vulnrichment
Node
repute_info_systemsarformsRange6.4wordpress
VendorProductVersionCPE
repute_info_systemsarforms*cpe:2.3:a:repute_info_systems:arforms:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "ARForms",
    "vendor": "Repute info systems",
    "versions": [
      {
        "changes": [
          {
            "at": "6.4.1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.4",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

9.0%