cve/2024/CVE-2024-37160.md
2024-06-18 02:51:15 +02:00

978 B

CVE-2024-37160

Description

Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execute arbitrary web scripts by modifying site options via /panel/options/site. This type of attack is suitable for persistence, affecting visitors across all pages (except the dashboard). This vulnerability is fixed in 1.13.1.

POC

Reference

Github

No PoCs found on GitHub currently.