10

CVE-2020-35489

Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
Mögliche Gegenmaßnahme
Contact Form 7: Update to version 5.3.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RocklobsterContact Form 7 SwPlatformwordpress Version < 5.3.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Contact Form 7
Version [*, 5.3.2)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.27% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://wordpress.org/plugins/contact-form-7/#developers
Third Party Advisory
Release Notes
https://contactform7.com/2020/12/17/contact-form-7-532/
Vendor Advisory
https://wpscan.com/vulnerability/10508
Third Party Advisory
https://www.getastra.com/blog/911/plugin-exploit/contact-form-7-unrestricted-file-upload/
Third Party Advisory
https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7/
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/c2f54e8d-9e81-4902-9111-b826ef5da164
Third Party Advisory