Vulnerabilities (CVE)

Filtered by vendor Appnitro Subscribe
Filtered by product Machform
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-6411 1 Appnitro 1 Machform 2018-06-29 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
CVE-2018-6410 1 Appnitro 1 Machform 2018-06-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.