CVE-2024-36572: Allpro Formmanager Data Handler

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

Affected products

  • Allpro Formmanager Data Handler: version 0.7.4 only

Published 2024-07-30. Last modified 2026-06-17.