S4E just found a medium-severity finding from log file scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0591 Scanner

CVE-2022-0591 scanner - Server-Side Request Forgery (SSRF) vulnerability in FormCraft

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
6.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0591
9.1
CVSS

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
FormCraft
AFFECTED< 3.8.28SAFE ✓≥ 3.8.28
Updated Sep 10, 2026View on NVD →
Detail

The FormCraft software is a popular WordPress plugin used for creating and managing custom forms on websites. It allows users to easily create various types of forms, such as contact forms, feedback forms, registration forms, and surveys, without needing to have any programming skills. Additionally, FormCraft offers advanced features like conditional logic, multi-page forms, file uploads, and integrations with popular email marketing and CRM tools. Overall, FormCraft aims to simplify the process of collecting and organizing data through web forms.

Recently, a security vulnerability was identified in FormCraft versions before 3.8.28, which could allow for SSRF (Server-Side Request Forgery) attacks. The vulnerability is identified by the code CVE-2022-0591 and occurs due to the plugin's failure to validate the URL parameter in the formcraft3_get AJAX action. With this vulnerability, an unauthenticated user could potentially send crafted requests that allow them to interact with internal systems, and this could lead to unauthorized access to sensitive data, among other things.

If exploited, the CVE-2022-0591 vulnerability can lead to security breaches, data theft, unauthorized access, and other harmful consequences. Cybercriminals can take advantage of this bug to bypass authentication and access sensitive information. This can result in financial loss, reputation damage, and regulatory penalties. Furthermore, the SSRF attacks can open backdoors for attackers to gain access to the server, its database, and other network resources. All these can lead to severe damage to an organization's digital assets and business operations.

In conclusion, it's essential to stay on top of software vulnerabilities that can harm digital assets. Thanks to the pro features of s4e.io, users can quickly identify potential threats to their digital assets and stay on top of security risks. With a vast database of vulnerabilities and proactive notifications that help users stay ahead of emerging threats, s4e.io provides an all-in-one solution for security. That way, users can focus on growing their businesses without worrying about being vulnerable to attacks.

 

REFERENCES

Solution Advice

To safeguard against the FormCraft vulnerability CVE-2022-0591, users have several precautions they can take. Some of these measures include the following: - Upgrade FormCraft to version 3.8.28 or later.

  • Configure the web server to validate and whitelist any user input.
  • Use a web application firewall (WAF) to filter out malicious requests.
  • Limit the exposure of internal systems to untrusted external networks.
  • Employ a secure design and coding approach when developing web applications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.