PoC Index

CVE-2024-38773

CRITICAL 9.8EPSS 2.0%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.17.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.3 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
EPSS
2.00% chance of exploitation in the next 30 days, 79th percentile
Nuclei
critical · CWE-89
Published
2024-07-22
Updated
2026-04-28

Nuclei templates (1)

References

Related