PT-2019-14854 · WordPress · Arforms

Ahmed Mohamed Almorabea

·

Publicado

2019-09-27

·

Atualizado

2021-07-21

·

CVE-2019-16902

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ARforms plugin version 3.7.1 for WordPress
Description The issue allows unauthenticated deletion of an arbitrary file by supplying the full pathname through the arf delete file function in arformcontroller.php.
Recommendations For ARforms plugin version 3.7.1, consider disabling the arf delete file function in arformcontroller.php to prevent unauthenticated file deletion until a patch is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16902

Produtos afetados

Arforms