Unauthenticated Attackers Can Modify Other Users' Quiz Submissions via Insecure Direct Object Reference in Forminator Forms
CVE-2024-9700
5.3MEDIUM
Key Information:
- Vendor
- Forminator Forms
- Status
- Forminator Forms
- Vendor
- CVE Published:
- 31 October 2024
Summary
The Forminator Forms plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) issue present in all versions up to and including 1.36.0. The vulnerability arises from the lack of proper validation on the 'entry_id' user-controlled key within the submit_quizzes() function. This flaw allows unauthenticated attackers to manipulate other users' quiz submissions, potentially leading to unauthorized data exposure and modifications. Website owners utilizing this plugin are advised to apply necessary security measures to mitigate the risk.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database