PT-2024-38571 · Bit Form · The Contact Form By Bit Form

Siunam

+1

·

Published

2024-08-19

·

Updated

2024-08-26

·

CVE-2024-7775

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Contact Form by Bit Form versions 2.0 through 2.13.9
Description The issue is related to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode function. This allows authenticated attackers with Administrator-level access and above to upload arbitrary JavaScript files to the affected site's server.
Recommendations For versions 2.0 through 2.13.9, consider disabling the addCustomCode function until a patch is available to prevent arbitrary JavaScript file uploads. Restrict access to the plugin's custom code feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-7775

Affected Products

The Contact Form By Bit Form