CVEs (1)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Advanced Forms Project 1Advanced Forms Nov 21, 2024 Nov 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead...Show more |