CVE-2022-24983
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.71% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- jqueryform/jqueryform
- Source
- cve@mitre.org
References
- https://JQueryForm.comVendor Advisory
- https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560Third Party Advisory
- https://www.nou-systems.com/cyber-securityThird Party Advisory
- https://JQueryForm.comVendor Advisory
- https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560Third Party Advisory
- https://www.nou-systems.com/cyber-securityThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.