Unauthenticated Attackers Can Modify Other Users' Quiz Submissions via Insecure Direct Object Reference in Forminator Forms

CVE-2024-9700

5.3MEDIUM

Key Information:

Vendor
Forminator Forms
Status
Forminator Forms
Vendor
CVE Published:
31 October 2024

Summary

The Forminator Forms plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) issue present in all versions up to and including 1.36.0. The vulnerability arises from the lack of proper validation on the 'entry_id' user-controlled key within the submit_quizzes() function. This flaw allows unauthenticated attackers to manipulate other users' quiz submissions, potentially leading to unauthorized data exposure and modifications. Website owners utilizing this plugin are advised to apply necessary security measures to mitigate the risk.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.