Impact
The vulnerability lies within the Multi‑User‑Selector AJAX endpoint of Forma LMS (versions up to 4.1.43). By manipulating the Name parameter sent to the endpoint /appCore/ajax.adm_server.php?r=adm/userselector/getData, an attacker can inject arbitrary SQL statements that are executed against the application’s database. This flaw permits execution of unintended queries, potentially exposing, altering, or destroying database contents, depending on the privileges of the process that handles the request.
Affected Systems
Forma LMS versions 4.1.43 and earlier are affected. Administrators or users who can access the /appCore/ajax.adm_server.php endpoint with the getDataTask function are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability is remotely reachable and publicly disclosed. The CISA KEV catalog does not list this issue. The likely attack vector is HTTP requests to the vulnerable endpoint, which can originate from anywhere on the internet.
OpenCVE Enrichment