Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48369 | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'fnsf_af2_handel_file_upload' function in all versions up to, and including, 3.7.3.2. This makes it possible for unauthenticated attackers to upload arbitrary media to the site, even if no forms exist. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 13 Sep 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Funnelforms funnelforms Free
|
|
| CPEs | cpe:2.3:a:funnelforms:funnelforms_free:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Funnelforms funnelforms Free
|
Wed, 28 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Funnelforms
Funnelforms interactive Contact Form And Multi Step Form Builder |
|
| CPEs | cpe:2.3:a:funnelforms:interactive_contact_form_and_multi_step_form_builder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Funnelforms
Funnelforms interactive Contact Form And Multi Step Form Builder |
|
| Metrics |
ssvc
|
Wed, 28 Aug 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'fnsf_af2_handel_file_upload' function in all versions up to, and including, 3.7.3.2. This makes it possible for unauthenticated attackers to upload arbitrary media to the site, even if no forms exist. | |
| Title | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Upload | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-28T13:25:43.796Z
Reserved: 2024-08-02T22:46:44.738Z
Link: CVE-2024-7447
Updated: 2024-08-28T13:25:38.872Z
Status : Analyzed
Published: 2024-08-28T12:15:06.620
Modified: 2024-09-13T19:33:25.957
Link: CVE-2024-7447
No data.
OpenCVE Enrichment
No data.
EUVD