PT-2018-9651 · Joomla · Convert Forms

Jetty Sairam

·

Publicado

2018-04-12

·

Atualizado

2019-10-03

·

CVE-2018-10063

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Convert Forms extension versions prior to 2.0.4
Description: The issue concerns a Remote Command Execution vulnerability using CSV Injection. This occurs when the software mishandles the export of a Leads file, allowing for potential exploitation.
Recommendations: For versions prior to 2.0.4, update to version 2.0.4 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-10063

Produtos afetados

Convert Forms