NA

CVE-2023-1112

Published: 01/03/2023 Updated: 11/04/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222072.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

codedropz drag and drop multiple file upload - contact form 7

Github Repositories

Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5.0.6.1 Path Traversal (CVE-2023-1112)

CVE-2023-1112 - Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5061 Path Traversal Info Path Traversal in Drag and Drop Multiple File Uploader PRO - Contact Form 7 version 5061 allows unauthenticated remote attacker to upload files anywhere writable on the remote server (CVE-2023-1112) To exploit this vulnerability, the attacker needs to upload a file using t