CVE-2024-28890Unrestricted File Upload in Forminator

Severity
5.3MEDIUMNVD
EPSS
0.9%
top 25.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23

Description

Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Affected Packages2 packages

NVDincsub/forminator< 1.29.0
CVEListV5wpmu_dev/forminatorprior to 1.29.0

🔴Vulnerability Details

2
GHSA
GHSA-5q9m-f76w-7rm3: Forminator prior to 12024-04-23
CVEList
CVE-2024-28890: Forminator prior to 12024-04-23
CVE-2024-28890 — Unrestricted File Upload in Forminator | cvebase