Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-22722. PoCs published by terribledactyl.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-22722, demonstrating a Server-Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1. The exploit automates the creation of a malicious form and group, leveraging the Group Name field to execute arbitrary commands via SSTI.
Description
Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.
Exploits (1)
This repository contains a functional Python exploit for CVE-2024-22722, demonstrating a Server-Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1. The exploit automates the creation of a malicious form and group, leveraging the Group Name field to execute arbitrary commands via SSTI.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H