Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
References
Configurations
History
21 Nov 2024, 05:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.tenable.com/security/research/tra-2021-25%2Chttps://www.machform.com/blog-machform-16-released/ - |
07 Nov 2023, 03:28
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-06-29 16:15
Updated : 2024-11-21 05:45
NVD link : CVE-2021-20104
Mitre link : CVE-2021-20104
CVE.ORG link : CVE-2021-20104
JSON object : View
Products Affected
machform
- machform
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type