An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.Referenceshttps://metalamin.github.io/MachForm-not-0-day-EN/https://www.exploit-db.com/exploits/44804/https://www.machform.com/blog-machform-423-security-release/