CVE-2023-1112: Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversal
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument uploadname leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222072.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1112?
The severity of CVE-2023-1112 is critical.
What is the affected software of CVE-2023-1112?
The affected software of CVE-2023-1112 is Drag and Drop Multiple File Uploader Pro - Contact Form 7 version 5.0.6.1 on WordPress.
What is the vulnerability description of CVE-2023-1112?
CVE-2023-1112 is a path traversal vulnerability in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress, allowing an attacker to execute arbitrary commands.
How can I fix CVE-2023-1112?
To fix CVE-2023-1112, it is recommended to update Drag and Drop Multiple File Uploader Pro - Contact Form 7 to the latest version and apply any available patches or security updates.
What is the Common Weakness Enumeration (CWE) of CVE-2023-1112?
The Common Weakness Enumeration (CWE) of CVE-2023-1112 is CWE-22 and CWE-23.