Ver todas as ameaças

CVE-2024-13498

Alvo: Não informado

Descrição

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention and lack of randomization of file names. This makes it possible for unauthenticated attackers to extract sensitive data including files uploaded via a form.

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2024-13498
Tags
Nâo informado
Data de publicação
12/03/2025
Última atualização
13/03/2025
Pontuação em CVSS 3.0
5.3
Médio
Rolar para cima