5.3
CVSSv3

CVE-2020-9364

Published: 04/03/2020 Updated: 06/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in helpers/mailer.php in the Creative Contact Form extension 4.6.2 prior to 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could exploit this vulnerability with the "Send me a copy" option to receive any files of the filesystem via email.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

creative-solutions creative contact form 4.6.2

Exploits

Creative Contact Form version 462 before Dec 03 2019 suffers from a directory traversal vulnerability ...