.. / CVE-2022-0591

Exploit for Formcraft3 <3.8.28 - Server-Side Request Forgery (CVE-2022-0591)

Description:

Formcraft3 before version 3.8.2 does not validate the URL parameter in the formcraft3_get AJAX action, leading to server-side request forgery issues exploitable by unauthenticated users.

Nuclei Template

View the template here CVE-2022-0591.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0591.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-0591
https://wpscan.com/vulnerability/b5303e63-d640-4178-9237-d0f524b13d47