CVE-2020-9364: Path Traversal
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactformupload parameter. An attacker could exploit this vulnerability with the "Send me a copy" option to receive any files of the filesystem via email.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-9364.
What is the affected software?
The affected software is Creative Contact Form extension version 4.6.2 for Joomla!.
What is the severity level of CVE-2020-9364?
The severity level of CVE-2020-9364 is medium with a CVSS score of 5.3.
What is the vulnerability description of CVE-2020-9364?
CVE-2020-9364 is a directory traversal vulnerability in the filename field for uploaded attachments via the creativecontactform_upload parameter in Creative Contact Form extension 4.6.2 for Joomla!.
How can this vulnerability be exploited?
An attacker can exploit CVE-2020-9364 by uploading malicious attachments with crafted filenames that allow them to traverse directories and potentially access sensitive files.