Skip to main content

Vendor/product archive

formtools / core CVEs

Beta · best-effort

3 CVEs tagged to formtools / core1 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-38145

Published Aug 31, 2021

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-38144

Published Aug 31, 2021

An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a form via the submission_id parameter, e.g., clients/forms/ed…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38143

Published Aug 31, 2021

An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to log in and proceed with a change of name…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1