PT-2023-21701 · Unknown · Snow Monkey Forms

CVE-2023-28413

·

Published

2023-05-23

·

Updated

2025-01-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snow Monkey Forms versions v5.0.6 and earlier
Description A directory traversal vulnerability allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
Recommendations For Snow Monkey Forms versions v5.0.6 and earlier, update to a version later than v5.0.6 to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories and files to minimize the risk of exploitation.

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28413

Affected Products

Snow Monkey Forms