Ver todas as ameaças

CVE-2023-0714

Alvo: Não informado

Descrição

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. This allows unauthenticated visitors to perform a “double extension” attack and upload files containing a malicious extension but ending with a benign extension, which may make remote code execution possible in some configurations.

Software
Não informado
Tipo Software
Core
CVE
CVE-2023-0714
Tags
Nâo informado
Data de publicação
17/08/2024
Última atualização
24/04/2025
Pontuação em CVSS 3.0
8.1
Alto
Rolar para cima