Description
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:32:02.170Z
Reserved: 2019-04-04T00:00:00.000Z
Link: CVE-2019-10869
No data.
Status : Modified
Published: 2019-05-07T18:29:01.223
Modified: 2024-11-21T04:20:00.563
Link: CVE-2019-10869
No data.
OpenCVE Enrichment
No data.