🔙 목록으로 돌아가기

CVE-2017-20194: Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure

TitleFormidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure
AuthorDhiyaneshDK
SeverityMedium
ImpactUnauthenticated attackers can export all form entries, leading to potential data breaches and privacy violations.
RemediationUpdate to version 2.05.04 or later.
CVSS Score5.3
EPSS Score0.10488
CVE IDCVE-2017-20194
CWE IDCWE-200
Tags cve cve2017 wpscan wordpress wp wp-plugin formidable passive vkev vuln

🔍 Vulnerability Description

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

🌐 HTTP Request

GET /wp-content/plugins/formidable/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-20194.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-20194.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A