CVE-2022-38400

medium

Description

Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a specially crafted URL.

References

https://www.synck.com/downloads/cgi-perl/mailformpro/index.html

https://www.synck.com/downloads/cgi-perl/mailformpro/feature_1381250709.html

https://www.synck.com/blogs/news/newsroom/detail_1661907555.html

https://jvn.jp/en/jp/JVN34205166/index.html

Details

Source: Mitre, NVD

Published: 2022-09-08

Updated: 2023-08-08

Risk Information

CVSS v2

Base Score: 5.4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.0019