First published: Wed Jan 22 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Multi Uploader for Gravity Forms allows Upload a Web Shell to a Web Server. This issue affects Multi Uploader for Gravity Forms: from n/a through 1.1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gravity Forms Multi Uploader | <=1.1.3 | |
Gravity Forms Multi Uploader for Gravity Forms | <=1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23921 is classified as a high severity vulnerability that allows the unrestricted upload of dangerous file types.
To fix CVE-2025-23921, update the Multi Uploader for Gravity Forms to version 1.1.4 or later.
CVE-2025-23921 can be exploited to upload a web shell to a web server, potentially enabling unauthorized access.
CVE-2025-23921 affects all versions of Multi Uploader for Gravity Forms up to and including version 1.1.3.
Users of Gravity Forms Multi Uploader for Gravity Forms version 1.1.3 and earlier are impacted by CVE-2025-23921.