|
|
| |
| |
CERT-In Vulnerability Note
CIVN-2020-0442
Multiple vulnerabilities in Contact Form 7
Original Issue Date:December 21, 2020
Severity Rating: HIGH
Software Affected
- Contact Form 7 5.3.1 and older versions
Overview
A vulnerability has been discovered in Contact Form 7 version 5.3.1 or older that allows an attacker to upload malicious scripts.
Description
An unrestricted file upload vulnerability is found in a Word Press plug-in. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access or privilege escalation. It allows an unauthenticated user to bypass any form file-type restrictions in Contact Form 7 and upload an executable binary to a site running the plug-in version 5.3.1 or earlier.
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
| | | |