CVE-2018-10063: High severity convert forms vulnerability
Published Apr 12, 2018
·Updated
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.
Affected Software
1 affected component
Convert Forms Project Convert Forms Joomla\!<2.0.4
Event History
Apr 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10063?
CVE-2018-10063 is classified as a critical vulnerability due to its potential for Remote Command Execution.
2
How do I fix CVE-2018-10063?
To fix CVE-2018-10063, upgrade the Convert Forms extension to version 2.0.4 or later.
3
What impact does CVE-2018-10063 have on Joomla! sites?
CVE-2018-10063 can allow attackers to execute arbitrary commands on affected Joomla! sites via crafted CSV files.
4
Which versions of Convert Forms are affected by CVE-2018-10063?
Versions of Convert Forms prior to 2.0.4 are affected by CVE-2018-10063.
5
Is CVE-2018-10063 specific to a particular platform?
Yes, CVE-2018-10063 specifically affects the Convert Forms extension for Joomla!.