CVE-2019-10869: Path Traversal
Published May 7, 2019
·Updated
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmpname parameters.
Affected Software
1 affected component
NinjaForms Ninja Forms File Uploads Wordpress<3.0.23
Event History
May 7, 2019
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-10869.
2
What is the severity of CVE-2019-10869?
The severity of CVE-2019-10869 is high.
3
Which software is affected by CVE-2019-10869?
The Ninja Forms plugin before version 3.0.23 for WordPress with the Uploads add-on activated is affected by CVE-2019-10869.
4
What is the impact of CVE-2019-10869?
CVE-2019-10869 allows an attacker to traverse the file system, access files, and execute code.
5
How can I fix the vulnerability CVE-2019-10869?
To fix CVE-2019-10869, update the Ninja Forms plugin to version 3.0.23 or later.