Vulnerability Note VU#494015
PHP FormMail Generator generates code with multiple vulnerabilities
PHP FormMail Generator is a single-instance website that generates PHP code for standard web forms for inclusion into PHP or WordPress websites. The generated code is vulnerable to authentication bypass and unsafe deserialization of untrusted data.
CWE-302: Authentication Bypass by Assumed-Immutable Data - CVE-2016-9482
A remote unauthenticated user may bypass authentication to access the administrator panel by navigating directly to:
An unauthenticated remote user may be able to gain access to the form's administrator panel, or obtain files from the server.
Regenerate your PHP form code
Vendor Information (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|PHP FormMail Generator||Affected||29 Nov 2016||08 Dec 2016|
CVSS Metrics (Learn More)
Thanks to Pouya Darabi for reporting this vulnerability.
This document was written by Garret Wassermann.
- CVE IDs: CVE-2016-9482 CVE-2016-9483 CVE-2016-9484
- Date Public: 05 Dec 2016
- Date First Published: 08 Dec 2016
- Date Last Updated: 08 Dec 2016
- Document Revision: 29
If you have feedback, comments, or additional information about this vulnerability, please send us email.