CVE-2023-32623

Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:2inc:snow_monkey_forms:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:03

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN97127032/ - Third Party Advisory () https://jvn.jp/en/jp/JVN97127032/ - Third Party Advisory
References () https://snow-monkey.2inc.org/2023/07/14/snow-monkey-forms-v5-1-2/ - Release Notes () https://snow-monkey.2inc.org/2023/07/14/snow-monkey-forms-v5-1-2/ - Release Notes

21 Jul 2023, 19:19

Type Values Removed Values Added
References (MISC) https://snow-monkey.2inc.org/2023/07/14/snow-monkey-forms-v5-1-2/ - (MISC) https://snow-monkey.2inc.org/2023/07/14/snow-monkey-forms-v5-1-2/ - Release Notes

19 Jul 2023, 03:15

Type Values Removed Values Added
References
  • {'url': 'https://snow-monkey.2inc.org/2023/06/22/snow-monkey-forms-v5-1-1/', 'name': 'https://snow-monkey.2inc.org/2023/06/22/snow-monkey-forms-v5-1-1/', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://snow-monkey.2inc.org/2023/07/14/snow-monkey-forms-v5-1-2/ -
Summary Directory traversal vulnerability in Snow Monkey Forms versions v5.1.0 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server. Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.

07 Jul 2023, 13:03

Type Values Removed Values Added
CPE cpe:2.3:a:2inc:snow_monkey_forms:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time 2inc snow Monkey Forms
2inc
CWE CWE-22
References (MISC) https://snow-monkey.2inc.org/2023/06/22/snow-monkey-forms-v5-1-1/ - (MISC) https://snow-monkey.2inc.org/2023/06/22/snow-monkey-forms-v5-1-1/ - Vendor Advisory
References (MISC) https://jvn.jp/en/jp/JVN97127032/ - (MISC) https://jvn.jp/en/jp/JVN97127032/ - Third Party Advisory

28 Jun 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-28 05:15

Updated : 2024-11-21 08:03


NVD link : CVE-2023-32623

Mitre link : CVE-2023-32623

CVE.ORG link : CVE-2023-32623


JSON object : View

Products Affected

2inc

  • snow_monkey_forms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')