Description
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
Published: 2019-05-07
Score: 8.1 High
EPSS: 48.0% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Ninjaforms Ninja Forms File Uploads
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:32:02.170Z

Reserved: 2019-04-04T00:00:00.000Z

Link: CVE-2019-10869

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-07T18:29:01.223

Modified: 2024-11-21T04:20:00.563

Link: CVE-2019-10869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses