CVE-2018-6411: Machform
Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
Affected products
- Machform Machform: version 4.2.3 only
Published 2018-05-26. Last modified 2026-06-17.