CVE-2024-22722

HIGH

Form Tools 3.1.1 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-22722. PoCs published by terribledactyl.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-22722, demonstrating a Server-Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1. The exploit automates the creation of a malicious form and group, leveraging the Group Name field to execute arbitrary commands via SSTI.

Description

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.

Exploits (1)

nomisec WORKING POC
by terribledactyl · poc
https://github.com/terribledactyl/Form-Tools-3.1.1-RCE

This repository contains a functional Python exploit for CVE-2024-22722, demonstrating a Server-Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1. The exploit automates the creation of a malicious form and group, leveraging the Group Name field to execute arbitrary commands via SSTI.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Form Tools 3.1.1
Auth required
Prerequisites: Valid admin credentials · Access to the Form Tools admin interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0089
EPSS Percentile 54.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
formtools/form_tools 3.1.1
Published Apr 11, 2024
Tracked Since Feb 18, 2026