PT-2022-20481 · Unknown · Open Forms

Sergei-Maertens

·

Published

2022-06-13

·

Updated

2022-06-23

·

CVE-2022-31041

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Open Forms versions prior to 1.0.9 Open Forms versions prior to 1.1.1
Description Open Forms is an application for creating and publishing smart forms, supporting file uploads with configurable allowed file extensions. The input validation of uploaded files is insufficient, allowing users to alter or strip file extensions and bypass validation. This results in files being uploaded to the server with different file types than indicated by the file name extension, potentially leading to malicious files entering internal networks.
Recommendations For versions prior to 1.0.9, update to version 1.0.9 or later to resolve the issue. For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider using an API gateway or intrusion detection solution in front of Open Forms to scan for and block malicious content before it reaches the application.

Exploit

Fix

Unrestricted File Upload

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31041
GHSA-H85R-XV4W-CG8G

Affected Products

Open Forms