First published: Fri May 17 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
BuddyForms | <=2.8.8 | |
BuddyForms | <=2.8.8 |
Update to 2.8.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32830 is classified as a high severity vulnerability due to its potential for server-side request forgery and path traversal exploitation.
To mitigate CVE-2024-32830, update the BuddyForms plugin to the latest version that addresses the vulnerability.
CVE-2024-32830 allows for server-side request forgery and relative path traversal, which could enable unauthorized access to sensitive files or services.
CVE-2024-32830 affects BuddyForms versions from n/a up to and including 2.8.8.
Users of the ThemeKraft BuddyForms plugin, specifically those using versions up to 2.8.8, are affected by CVE-2024-32830.