Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:32:02.170Z

Reserved: 2019-04-04T00:00:00

Link: CVE-2019-10869

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-07T18:29:01.223

Modified: 2024-11-21T04:20:00.563

Link: CVE-2019-10869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses