CVE-2018-5991

CRITICAL

Joomla! Form Maker 3.6.12 - SQL Injection

Title source: llm

Description

SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/44111

Scores

CVSS v3 9.8
EPSS 0.0045
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
web-dorado/form_maker 3.6.12
Published Feb 17, 2018
Tracked Since Feb 18, 2026