9.1
CVSSv3

CVE-2022-0591

Published: 21/03/2022 Updated: 28/03/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The FormCraft WordPress plugin prior to 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

subtlewebinc formcraft3

Github Repositories

Automatic Mass Tool for checking vulnerability in CVE-2022-0591 - Formcraft3 < 3.8.28 - Unauthenticated SSRF

FC3er | CVE-2022-0591 - Formcraft3 Automatic Mass Tool for checking vulnerability in CVE-2022-0591 - Formcraft3 &lt; 3828 - Unauthenticated SSRFUsing GNU Parallel You must have parallel for running this tool If you found error like "$'\r': command not found" just do "dos2unix fc3ersh" Install Parallel Linux : apt-get install parallel -y