THREATOPS
THREAT OPSThreat News › [NVD] CVE-2019-10869 (HIGH 8.1) — Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/sub

[NVD] CVE-2019-10869 (HIGH 8.1) — Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/sub

lownvdPublished 2019-05-07

CVE-2019-10869 CVSS: 8.1 HIGH Published: 2019-05-07T18:29:01.223

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2019-10869