PT-2024-39618 · WordPress · The Hash Form – Drag & Drop Form Builder

Rein Daelman

+1

·

Published

2024-10-05

·

Updated

2024-10-07

·

CVE-2024-9417

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Hash Form – Drag & Drop Form Builder plugin for WordPress versions up to, and including, 1.1.9
Description The issue is related to a misconfigured file type validation in the handleUpload function, allowing unauthenticated attackers to upload files that are excluded from both the allowedExtensions and unallowed extensions arrays on the affected site's server. This includes files that may contain cross-site scripting.
Recommendations For versions up to, and including, 1.1.9, update to a version that fixes the misconfigured file type validation issue in the handleUpload function to prevent unauthenticated file uploads. As a temporary workaround, consider disabling the handleUpload function until a patch is available. Restrict access to file uploads to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-9417

Affected Products

The Hash Form – Drag & Drop Form Builder