THREAT OPS › Threat News › [NVD] CVE-2019-10869 (HIGH 8.1) — Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/sub
[NVD] CVE-2019-10869 (HIGH 8.1) — Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/sub
CVE-2019-10869 CVSS: 8.1 HIGH Published: 2019-05-07T18:29:01.223
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
Indicators of compromise
- CVE-2019-10869cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2019-10869