PT-2023-21701 · Unknown · Snow Monkey Forms
Published
2023-05-23
·
Updated
2025-01-31
·
CVE-2023-28413
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Snow Monkey Forms versions v5.0.6 and earlier
Description
A directory traversal vulnerability allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
Recommendations
For Snow Monkey Forms versions v5.0.6 and earlier, update to a version later than v5.0.6 to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories and files to minimize the risk of exploitation.
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snow Monkey Forms