6.8
CVSSv2

CVE-2019-10869

Published: 07/05/2019 Updated: 02/05/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin prior to 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an malicious user to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ninjaforms ninja forms file uploads

Github Repositories

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

CVE-2019-10869 (Wordpress) Ninja Forms File Uploads Extension &lt;= 3022 – Unauthenticated Arbitrary File Upload Description: Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3023 for WordPress (when the Uploads add-on is activated) This allows an attacker to traverse the file system to access files and execute code via the incl