1 results (0.003 seconds)
CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 4

CVE-2020-9364 – Creative Contact Form 4.6.2 Directory Traversal
https://notcve.org/view.php?id=CVE-2020-9364
04 Mar 2020 — An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could exploit this vulnerability with the "Send me a copy" option to receive any files of the filesystem via email. Se detectó un problema en el archivo helpers/mailer.php en la extension Creative Contact Form versiones anteriores a 4.6.2 ha... • https://packetstorm.news/files/id/156655 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •