PT-2022-20481 · Unknown · Open Forms
Sergei-Maertens
·
Published
2022-06-13
·
Updated
2022-06-23
·
CVE-2022-31041
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Open Forms versions prior to 1.0.9
Open Forms versions prior to 1.1.1
Description
Open Forms is an application for creating and publishing smart forms, supporting file uploads with configurable allowed file extensions. The input validation of uploaded files is insufficient, allowing users to alter or strip file extensions and bypass validation. This results in files being uploaded to the server with different file types than indicated by the file name extension, potentially leading to malicious files entering internal networks.
Recommendations
For versions prior to 1.0.9, update to version 1.0.9 or later to resolve the issue.
For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue.
As a temporary workaround, consider using an API gateway or intrusion detection solution in front of Open Forms to scan for and block malicious content before it reaches the application.
Exploit
Fix
Unrestricted File Upload
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Forms