Junglewise Threat Intelligence

CVE-2026-78837: AppNitro MachForm SQL injection in ap_form parameter

CVE-2026-78837 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

AppNitro MachForm is a form-building platform used to create and manage online forms. A SQL injection vulnerability in form handling allows unauthenticated attackers to inject malicious SQL code, potentially exposing sensitive database information stored in form submissions and customer data.

Technical details

The vulnerability is a SQL injection flaw in the ap_form_{id} parameter and filter[filters][0][field] parameter processed by grid_datasource.php. An unauthenticated attacker can craft malicious SQL statements to enumerate database schema and extract sensitive data. The attack requires network access to the vulnerable endpoint but no authentication or user interaction. An attacker can enumerate valid column names in database tables and extract sensitive information including form submissions and customer data. Patches for MachForm v30 should be applied immediately.

Affected products

  • AppNitro MachForm v30

Timeline

  • 2026-09-08: disclosed

References

Related threats