Описание
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.6 (исключая)
cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 99%
0.72422
Высокий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 9.8
github
больше 1 года назад
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
EPSS
Процентиль: 99%
0.72422
Высокий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo