CVE-2024-6937 is a problematic file inclusion vulnerability in formtools.org Form Tools version 3.1.1, specifically within the curl_exec function of the /admin/forms/option_lists/edit.php component when handling the 'url' argument. This flaw allows a remote attacker to include arbitrary files. The vulnerability has a low CVSS score of 2.7, indicating low severity, and requires high privileges (PR:H) for exploitation, with a low impact on confidentiality (C:L) and no impact on integrity or availability. The attack complexity is low (AC:L), and no user interaction is required. Exploit code for this vulnerability has been publicly disclosed, though it is not present in common exploit frameworks like Metasploit or Nuclei. Despite public disclosure, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.1CPE matchmatch criteria | cpe:2.3:a:formtools:form_tools:3.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.