CVE-2019-17399: Path Traversal
Published Oct 9, 2019
·Updated
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
Affected Software
1 affected component
Joomlashack Shack Forms Pro Joomla\!<4.0.32
Event History
Oct 9, 2019
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed remotely with low complexity, without authentication or user interaction.
2
What security impact could successful exploitation have?
The vulnerability is rated critical with a CVSS 3.1 score of 9.8 and is assessed to have high confidentiality, integrity, and availability impact.
3
Which installations are affected?
Shack Forms Pro for Joomla! versions before 4.0.32 are affected.
4
What is the available remediation?
Update Shack Forms Pro to version 4.0.32 or later, as the affected range is versions before 4.0.32.