CVE-2018-19796: Medium severity ninja forms vulnerability
Published Dec 3, 2018
·Updated
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.3.19.1
Event History
Dec 3, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-19796.
2
What is the title of the vulnerability?
The title of the vulnerability is 'An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to ...'
3
What is the affected software?
The affected software is Ninja Forms plugin before version 3.3.19.1 for WordPress.
4
What is the severity rating of CVE-2018-19796?
The severity rating of CVE-2018-19796 is medium.
5
How can I fix the vulnerability?
To fix the vulnerability, update the Ninja Forms plugin to version 3.3.19.1 or later.